Executive brief
DBI is a Perl database interface library used by applications to access various databases. A flaw in DBD::DBM allows an attacker to load and execute arbitrary Perl modules by manipulating the dbm_type or dbm_mldbm connection attributes, potentially leading to code execution. An attacker with the ability to influence database connection parameters—such as through a DSN string or configuration option—can exploit this to run malicious code.
Technical details
DBD::DBM passes the dbm_type and dbm_mldbm attributes directly to Perl's require function without validating that they are valid module names. Since require treats path-shaped strings as literal filenames rather than consulting @INC, an attacker can traverse the filesystem using relative paths (e.g., "../../Untrusted.pm") to load arbitrary .pm files. The fix validates these attributes using Module::Load and a class name check before loading modules.
Affected products
- Perl DBI DBI before 1.653
Timeline
- 2026-09-19: disclosed
- 2026-08-22: patched: Fix committed to DBI repository