{"id":"CVE-2026-15392","summary":"DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location","details":"DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location.\n\nThe complete_table_name method builds the absolute table file path without checking whether the file is a symbolic link. A link inside the data directory can point to a table file at any path outside of the configured f_dir and f_dir_search directories.\n\nCallers of file-based drivers can read or write files outside of the data directory.","aliases":["GHSA-mh3j-xwf4-jrqw"],"modified":"2026-07-18T08:59:27.456330445Z","published":"2026-07-14T15:34:01.547Z","related":["openSUSE-SU-2026:11298-1"],"database_specific":{"cna_assigner":"CPANSec","cwe_ids":["CWE-22","CWE-59"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/15xxx/CVE-2026-15392.json"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/07/14/15"},{"type":"WEB","url":"https://cpan.org/modules"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/15xxx/CVE-2026-15392.json"},{"type":"ADVISORY","url":"https://github.com/perl5-dbi/dbi/security/advisories/GHSA-mh3j-xwf4-jrqw"},{"type":"ADVISORY","url":"https://metacpan.org/release/HMBRAND/DBI-1.651/changes"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15392"},{"type":"FIX","url":"https://github.com/perl5-dbi/dbi/commit/96d62dfe4528bf56fe13f413ed323d4252531728.patch"},{"type":"PACKAGE","url":"https://github.com/perl5-dbi/dbi"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/perl5-dbi/dbi","events":[{"introduced":"0"},{"fixed":"042b14366406a0654f345bd5e8ddec43dfc8800b"},{"fixed":"96d62dfe4528bf56fe13f413ed323d4252531728"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.651"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["1.650","1.649","1.648","1.647","1.646","1.645","1.644","1.643_02","1.643_01","1.643","1.642","1.641","1.640","1.639","1.638","1.637","1.636","1.635","1.634","1.633_92","1.633_91","1.633_90","1.633","1.632_90","1.632","1.631","1.630","1.628","1.627","1.626","1.625","1.624","1.622","1.619","1.618","1.615","1.614_90","1.613_93","1.613_92","1.613_91","1.613_90","1.613_71","1.613_70","1.611_94","1.611_93","1.611_92","1.611_91","1.611_90","1.607","1.602","DBI-1.58","DBI-1.57","DBI-1.51","DBI-1.47"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-15392.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}