What is CVE-2026-13048?
CVE-2026-13048 is a critical vulnerability in Data::MuForm::Localizer versions through 0.05 for Perl, where load_lexicon interpolates the language attribute into the catalog filename. This allows execution of arbitrary Perl code from a message catalog header via a crafted path. Immediate upgrade or removal of the module is required.
Azərbaycanca: CVE-2026-13048, Perl üçün Data::MuForm::Localizer modulunun 0.05-ə qədər versiyalarında aşkar edilmiş kritik boşluqdur. load_lexicon funksiyası dil atributunu fayl yoluna daxil etdiyi üçün, fərqli kataloqdakı zərərli Perl kodu icra oluna bilər. Təcili olaraq modulu yeniləmək və ya istifadədən çıxarmaq lazımdır.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which versions of Data::MuForm::Localizer are affected by CVE-2026-13048?
This vulnerability affects all versions of Data::MuForm::Localizer through 0.05 for Perl.
How does CVE-2026-13048 lead to arbitrary Perl code execution?
The vulnerability lies in the load_lexicon function, which interpolates the language attribute directly into the catalog filename. This allows execution of arbitrary Perl code from a message catalog header via a crafted path.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.