Impact
YAML versions before 1.27_001 for Perl allow a loaded perl/glob document to replace any package variable. Because the module imposes no restrictions on variable names, an attacker can target critical internal variables such as @INC or YAML's own load options. By setting $YAML::LoadCode or $YAML::UseCode to true, code loading is enabled for subsequent Load() calls, and a following perl/code document is executed through a string eval, which facilitates arbitrary Perl code execution in the same process.
Affected Systems
Perl module YAML is affected. Any installation of the YAML package with a version earlier than 1.27_001 is vulnerable. The issue is present in all prior releases; upgrading to 1.28 or later removes the ability to reinterpret package variables from loaded documents.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. EPSS data is not available, and the vulnerability is not listed in KEV, so the exploitation probability cannot be quantified. Based on the description, it is inferred that the attacker must be able to submit two YAML documents to consecutive Load() calls within the same process. If an application accepts user‑supplied YAML, this can be carried out either locally or remotely, enabling an attacker to execute arbitrary Perl code and potentially compromise the host system or application.
OpenCVE Enrichment