{"id":"CVE-2026-75031","details":"In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the \n“quick question” admin feature. In default installations arbitrary Perl \ncode can be injected and executed server-side by unauthenticated users. \nThe Perl code normally runs within a Safe container which limits the \nscope of what it can do, unless the non-default AllowGlobal directive is\n configured for the catalog being accessed.CTOR]","modified":"2026-09-20T11:47:12.379857668Z","published":"2026-09-18T15:20:40.925Z","database_specific":{"unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"fixed":"*"}]}],"cna_assigner":"redhat-cnalr","cwe_ids":["CWE-94"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75031.json"},"references":[{"type":"WEB","url":"https://github.com/interchange/interchange/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75031.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75031"},{"type":"ADVISORY","url":"https://www.interchangecommerce.org/i/dev/news?mv_arg=00071"},{"type":"FIX","url":"https://github.com/interchange/interchange/commit/65b6ea9d3761dd1fd2071c962819562afa335e4e"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/interchange/interchange","events":[{"introduced":"0"},{"fixed":"65b6ea9d3761dd1fd2071c962819562afa335e4e"}],"database_specific":{"source":"REFERENCES"}}],"versions":["REL_5_8_2","DEB_5_7_7_1","REL_5_7_7","REL_5_7_5","REL_5_7_4","REL_5_7_3","REL_5_7_2","REL_5_7_1","STABLE_5_6-root","REL_5_5_1","REL_5_5_2","STABLE_5_4-root","REL_5_3_2","DEB_5_3_0_20051028_1","DEB_5_3_0_20051004_1","STABLE_5_2-root","STABLE_5_0-root","REL_5_0_0_RC2","REL_5_0_0","REL_5_0_0_RC1","REL_4_9_9","DEB_4_9_8_20031014_1","DEB_4_9_8_20031010_1","DEB_4_9_8_20030911_1","DEB_4_9_8_20030706_1","DEB_4_9_8_2","REL_4_9_8","REL_4_9_6","REL_4_9_5","REL_4_9_4","REL_4_9_2","REL_4_9_1","STABLE_4_8-root","PRE_REL_4_8_0","REL_4_7_7","REL_4_7_6","STABLE_4_6-root","REL_4_6_4","REL_4_6_3","REL_4_6_2","REL_4_6_1","REL_4_5_8","REL_4_5_6","MV_4_5_0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75031.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}