Vulnerability Description
Sub::HandlesVia for Perl before 0.050002 allows untrusted code from the current working directory ('.') to be loaded similar to CVE-2016-1238. If an attacker can place a malicious file in current working directory, it may be loaded instead of the intended file, potentially leading to arbitrary code execution. Sub::HandlesVia uses Mite to produce the affected code section due to CVE-2025-30672
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://blogs.perl.org/users/todd_rinaldo/2016/11/what-happened-to-dot-in-inc.ht
- https://metacpan.org/dist/Sub-HandlesVia/changes#L12
- https://metacpan.org/release/TOBYINK/Sub-HandlesVia-0.050001/source/lib/Sub/Hand
FAQ
What is CVE-2025-30673?
CVE-2025-30673 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Sub::HandlesVia for Perl before 0.050002 allows untrusted code from the current working directory ('.') to be loaded similar to CVE-2016-1238. If an attacker can place a malicious file in current wor...
How severe is CVE-2025-30673?
CVE-2025-30673 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-30673?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.