Impact
YAML versions before 1.30 for Perl permit an attacker to craft a YAML document that triggers the DESTROY method of any class that the process has loaded. The YAML processor blesses a hash into the specified class; when the document's object goes out of scope Perl invokes DESTROY. Depending on the class, that method can perform destructive actions such as deleting files or executing arbitrary code. For example, with File::Temp::Dir from core Perl, DESTROY removes an entire directory tree that the document names, leading to data loss or service interruption.
Affected Systems
Perl installations that use the YAML module in any version earlier than 1.30 are susceptible. The vulnerability is present in the standard CPAN YAML package and affects any application that loads untrusted YAML documents without preventing object deserialization.
Risk and Exploitability
The vulnerability can be exploited by an attacker who can supply a crafted YAML file to an application. The CVSS score of 7.4 indicates a high severity. A successful exploit may lead to arbitrary code execution or destructive file system operations, depending on the classes loaded in the process. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, but the lack of a mitigation path and the potential for serious impact warrant immediate attention. The documented workaround—setting $YAML::LoadBlessed = 0 before loading untrusted input—reduces the risk by preventing arbitrary classes from being instantiated, though it remains a temporary measure until an upgrade can be performed.
OpenCVE Enrichment