PT-2026-48114 · Petdance+5 · App::Ack+2

·

CVE-2026-49145

·

Published

2026-06-08

·

Updated

2026-07-08

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions App::Ack versions prior to 3.10.0
Description The software searches the directory hierarchy for a project .ackrc file and loads its options. Because the project-source option blocklist in App::Ack::ConfigLoader does not include the --files-from parameter, a maliciously crafted .ackrc file in an untrusted repository can specify a path to arbitrary files. This allows the application to read and print matching lines from files located outside the project directory.
Recommendations Update to version 3.10.0 or later.

Exploit

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49145
OPENSUSE-SU-2026:10965-1

Affected Products

App::Ack
Ack
Ack3