PT-2026-43488 · Unknown+1 · Io::Compress+2

·

CVE-2026-48962

·

Published

2026-05-27

·

Updated

2026-07-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IO::Compress versions prior to 2.220
Description An issue in File::GlobMapper allows the execution of arbitrary code through an attacker-controlled output glob. The function parseOutputGlob() wraps the provided output glob string in double quotes and stores it in the parser state. Subsequently, the getFiles() function executes the stored expression using eval STRING. A literal double quote within the output glob can close the double quote wrapper, causing the subsequent characters to be evaluated as Perl code. This code executes with the privileges of the calling process.
Recommendations Update to version 2.220 or later.

Exploit

Fix

Code Injection

Eval Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:30851
ALSA-2026:30858
ALSA-2026:30859
ALSA-2026:30860
CVE-2026-48962
ECHO-FB2A-578C-BE2D
OESA-2026-2652
OESA-2026-2653
OESA-2026-2654
OPENSUSE-SU-2026:10939-1
OPENSUSE-SU-2026:21177-1
RHSA-2026:29182
RHSA-2026:29210
RHSA-2026:29867
RHSA-2026:29941
RHSA-2026:30085
RHSA-2026:30086
RHSA-2026:30115
RHSA-2026:30843
RHSA-2026:30858
RHSA-2026:30859
RHSA-2026:30860

Affected Products

File::Globmapper
Io::Compress
Rocky Linux