Description
Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename.

load_lexicon builds the catalog path by appending `Messages/$lang.po` to the directory holding Localizer.pm, where $lang is the language attribute, with no check that it names a bare locale tag. A value holding `../` segments walks out of the message directory, so any readable path with a `.po` suffix is loaded. While parsing the catalog, extract_header_msgstr takes the `Plural-Forms:` header, prefixes `$` to the bare words nplurals, plural and n, and passes the rest verbatim into a string that is evaluated: the nplurals form evaluates the header expression immediately, and the plural_code form compiles it into a subroutine whose body runs when a plural message is localized. A header of `nplurals=2; plural=(system('...'),0);` therefore runs that command as the catalog loads. The evaluation inherits strict, so an expression that assigns to an undeclared variable fails to compile, while one built from calls alone does not.

An application that sets the language attribute from request data, an Accept-Language header or a locale parameter, and an attacker who can place a file with a `.po` suffix and chosen contents at a readable path, together give code execution as the application user. The message expansion path is not affected: expand_named substitutes only the placeholder names the caller supplies, and _mangle_value returns the value unchanged.
Published: 2026-08-13
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Data::MuForm::Localizer through version 0.05 constructs a message catalog path using an unvalidated language attribute, allowing path traversal to any readable .po file. The catalog’s Plural-Forms header is parsed and evaluated, so an attacker can embed Perl code that is executed when the catalog loads. This defect enables arbitrary code execution with the privileges of the running application, exposing it to fully compromising the host and data it serves. The weakness is a combination of path traversal (CWE-22) and command injection via code evaluation (CWE-95).

Affected Systems

The vulnerability affects the Data::MuForm::Localizer Perl module in all releases up to and including 0.05. No other vendors or products are listed; the issue is contained to this module’s handling of the language attribute and message catalog loading mechanisms.

Risk and Exploitability

Because the flaw permits execution from an attacker-controlled .po file that can be referenced through a manipulated language attribute supplied in request data (such as a URL or Accept-Language header), the likely attack vector is a web request. The exploit requires the attacker to have write access to the file system at a location with a .po suffix, and the application must be running with permissions sufficient to read that file. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, but the nature of remote code execution and the lack of input validation elevate the risk to high. Applying the available patch is strongly recommended to mitigate the risk before exploitation can fully materialize.

Generated by OpenCVE AI on August 13, 2026 at 17:28 UTC.

Remediation

Vendor Workaround

No fixed release is available, and the distribution has not been updated since 2018. Apply the patch, which requires the language attribute to be a bare locale tag and parses the Plural-Forms header against the gettext plural grammar before it is evaluated. Deployments that cannot patch should not set the language attribute from request data, and should map any request supplied locale through a fixed table of supported tags before passing it to a form or localizer.


OpenCVE Recommended Actions

  • Apply the community patch to Data::MuForm::Localizer that validates the language attribute and parses the Plural-Forms header safely.
  • Configure the application to allow the language attribute only to be set from a whitelist of supported locale tags rather than from arbitrary request data.
  • If the patch cannot be applied, remove or sanitize the language attribute supplied via requests and restrict file system access to the message catalog directory to prevent traversal to other files.

Generated by OpenCVE AI on August 13, 2026 at 17:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename. load_lexicon builds the catalog path by appending `Messages/$lang.po` to the directory holding Localizer.pm, where $lang is the language attribute, with no check that it names a bare locale tag. A value holding `../` segments walks out of the message directory, so any readable path with a `.po` suffix is loaded. While parsing the catalog, extract_header_msgstr takes the `Plural-Forms:` header, prefixes `$` to the bare words nplurals, plural and n, and passes the rest verbatim into a string that is evaluated: the nplurals form evaluates the header expression immediately, and the plural_code form compiles it into a subroutine whose body runs when a plural message is localized. A header of `nplurals=2; plural=(system('...'),0);` therefore runs that command as the catalog loads. The evaluation inherits strict, so an expression that assigns to an undeclared variable fails to compile, while one built from calls alone does not. An application that sets the language attribute from request data, an Accept-Language header or a locale parameter, and an attacker who can place a file with a `.po` suffix and chosen contents at a readable path, together give code execution as the application user. The message expansion path is not affected: expand_named substitutes only the placeholder names the caller supplies, and _mangle_value returns the value unchanged.
Title Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename
Weaknesses CWE-22
CWE-95
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-08-13T16:28:25.637Z

Reserved: 2026-06-23T17:35:41.013Z

Link: CVE-2026-13048

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T17:17:19.397

Modified: 2026-08-13T17:17:19.397

Link: CVE-2026-13048

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T17:30:07Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-95

    Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')