Impact
DBI versions released before 1.650 for Perl contain a code injection flaw. When a caller supplies a string to the DBI handle’s Profile attribute, the library splits the string, extracts a package name, and evaluates that name with no validation. This allows an attacker to inject arbitrary Perl code that can invoke system commands. The consequence is full compromise of the host process, exposing confidentiality, integrity, and availability of the affected system.
Affected Systems
The vulnerability affects the HMBRAND DBI library in all releases prior to 1.650. It can be triggered from any source that populates the DBI Profile attribute, including the environment variable DBI_PROFILE, direct attribute assignments in code, or the DSN driver-attribute clause dbi:Driver(Profile=>SPEC):db. Systems that use DBI without restricting these inputs are at risk.
Risk and Exploitability
Remote code execution is the highest tier of impact. The CVSS score of 8.8 indicates high severity; the EPSS score of < 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. A network‑exposed DBI::Gofer or DBI::ProxyServer is the strongest remote surface, where a client can craft a per‑request DSN that reaches the Profile attribute and run code on the broker host. Even though EPSS is low, the direct eval path means that if an attacker can influence any Profile input, exploitation remains straightforward.
OpenCVE Enrichment