CVE-2026-13048: CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename. load_lexicon builds the catalog path by appending `Messages/$lang.po` to the directory holding Localizer.pm, where $lang is the language attribute, with no check that it names a bare locale tag. A value holding `../` segments walks out of the message directory, so any readable path with a `.po` suffix is loaded. While parsing the catalog, extract_header_msgstr takes the `Plural-Forms:` header, prefixes `$` to the bare words nplurals, plural and n, and passes the rest verbatim into a string that is evaluated: the nplurals form evaluates the header expression immediately, and the plural_code form compiles it into a subroutine whose body runs when a plural message is localized. A header of `nplurals=2; plural=(system('...'),0);` therefore runs that command as the catalog loads. The evaluation inherits strict, so an expression that assigns to an undeclared variable fails to compile, while one built from calls alone does not. An application that sets the language attribute from request data, an Accept-Language header or a locale parameter, and an attacker who can place a file with a `.po` suffix and chosen contents at a readable path, together give code execution as the application user. The message expansion path is not affected: expand_named substitutes only the placeholder names the caller supplies, and _mangle_value returns the value unchanged.
AI Analysis
Technical Summary
The vulnerability in Data::MuForm::Localizer (<=0.05) arises from the load_lexicon function, which constructs a catalog file path by appending 'Messages/$lang.po' to the module directory without validating that $lang is a safe locale tag. This allows path traversal via '../' sequences to load arbitrary .po files. The extract_header_msgstr function extracts the 'Plural-Forms:' header and evaluates its content as Perl code, including the nplurals and plural expressions. Because the plural expression is compiled into a subroutine and evaluated, an attacker who can control the .po file content can execute arbitrary Perl code. This leads to arbitrary code execution if the language attribute is set from untrusted input and the attacker can place malicious .po files at readable paths.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary Perl code with the privileges of the application user. This can lead to full compromise of the application environment. The vulnerability requires the attacker to control the language attribute input and to place a crafted .po file in a location readable by the application. There are no known exploits in the wild as of the published date.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, do not allow untrusted input to control the language attribute used by Data::MuForm::Localizer. Restrict file system permissions to prevent attackers from placing arbitrary .po files in locations readable by the application. Validate or sanitize the language attribute to prevent path traversal sequences.
CVE-2026-13048: CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
Description
Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename. load_lexicon builds the catalog path by appending `Messages/$lang.po` to the directory holding Localizer.pm, where $lang is the language attribute, with no check that it names a bare locale tag. A value holding `../` segments walks out of the message directory, so any readable path with a `.po` suffix is loaded. While parsing the catalog, extract_header_msgstr takes the `Plural-Forms:` header, prefixes `$` to the bare words nplurals, plural and n, and passes the rest verbatim into a string that is evaluated: the nplurals form evaluates the header expression immediately, and the plural_code form compiles it into a subroutine whose body runs when a plural message is localized. A header of `nplurals=2; plural=(system('...'),0);` therefore runs that command as the catalog loads. The evaluation inherits strict, so an expression that assigns to an undeclared variable fails to compile, while one built from calls alone does not. An application that sets the language attribute from request data, an Accept-Language header or a locale parameter, and an attacker who can place a file with a `.po` suffix and chosen contents at a readable path, together give code execution as the application user. The message expansion path is not affected: expand_named substitutes only the placeholder names the caller supplies, and _mangle_value returns the value unchanged.
CVSS v3.1
Score 8.2high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Data::MuForm::Localizer (<=0.05) arises from the load_lexicon function, which constructs a catalog file path by appending 'Messages/$lang.po' to the module directory without validating that $lang is a safe locale tag. This allows path traversal via '../' sequences to load arbitrary .po files. The extract_header_msgstr function extracts the 'Plural-Forms:' header and evaluates its content as Perl code, including the nplurals and plural expressions. Because the plural expression is compiled into a subroutine and evaluated, an attacker who can control the .po file content can execute arbitrary Perl code. This leads to arbitrary code execution if the language attribute is set from untrusted input and the attacker can place malicious .po files at readable paths.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary Perl code with the privileges of the application user. This can lead to full compromise of the application environment. The vulnerability requires the attacker to control the language attribute input and to place a crafted .po file in a location readable by the application. There are no known exploits in the wild as of the published date.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, do not allow untrusted input to control the language attribute used by Data::MuForm::Localizer. Restrict file system permissions to prevent attackers from placing arbitrary .po files in locations readable by the application. Validate or sanitize the language attribute to prevent path traversal sequences.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CPANSec
- Date Reserved
- 2026-06-23T17:35:41.013Z
- State
- PUBLISHED
Threat ID: 6a7df3d6bf8831d539788818
Added to database: 08/13/2026, 16:41:58 UTC
Last enriched: 08/13/2026, 17:01:05 UTC
Last updated: 09/26/2026, 13:47:42 UTC
Views: 54
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.