{"id":"CVE-2025-30673","summary":"Sub::HandlesVia for Perl allows untrusted code to be included from the current working directory","details":"Sub::HandlesVia for Perl before 0.050002 allows untrusted code from the current working directory ('.') to be loaded similar to CVE-2016-1238.\n\nIf an attacker can place a malicious file in current working directory, it may be loaded instead of the intended file, potentially leading to arbitrary code execution.\n\nSub::HandlesVia uses Mite to produce the affected code section due to CVE-2025-30672","modified":"2026-08-12T03:51:09.217975383Z","published":"2025-04-01T02:02:25.594Z","database_specific":{"cna_assigner":"CPANSec","cwe_ids":["CWE-427"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30673.json"},"references":[{"type":"WEB","url":"https://cpan.org/modules"},{"type":"WEB","url":"https://metacpan.org/dist/Sub-HandlesVia/changes#L12"},{"type":"WEB","url":"https://metacpan.org/release/TOBYINK/Sub-HandlesVia-0.050001/source/lib/Sub/HandlesVia/Mite.pm#L114"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30673.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30673"},{"type":"PACKAGE","url":"https://github.com/tobyink/p5-sub-handlesvia"},{"type":"ARTICLE","url":"https://blogs.perl.org/users/todd_rinaldo/2016/11/what-happened-to-dot-in-inc.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tobyink/p5-sub-handlesvia","events":[{"introduced":"0"},{"fixed":"39e36bfbe8a90ddc9dc5608f285f6112278b71fa"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.050002"}],"source":"AFFECTED_FIELD"}}],"versions":["0.050001","0.050000","0.046","0.045","0.044","0.043","0.042","0.041","0.040","0.039","0.038","0.037","0.036","0.035","0.034","0.033","0.032","0.031","0.030","0.029","0.028","0.027","0.026","0.025","0.024","0.023","0.022","0.021","0.020","0.019","0.018","0.017","0.016","0.015","0.014","0.013","0.012","0.011","0.010","0.009","0.008_003","0.008_002","0.008_001","0.008_000","0.007","0.006","0.005","0.004","0.003","0.002","0.001"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-30673.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}