PT-2026-48114 · Petdance+5 · App::Ack+2
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
App::Ack versions prior to 3.10.0
Description
The software searches the directory hierarchy for a project
.ackrc file and loads its options. Because the project-source option blocklist in App::Ack::ConfigLoader does not include the --files-from parameter, a maliciously crafted .ackrc file in an untrusted repository can specify a path to arbitrary files. This allows the application to read and print matching lines from files located outside the project directory.Recommendations
Update to version 3.10.0 or later.
Exploit
Fix
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
App::Ack
Ack
Ack3