Description
App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc.

ack searches up the directory hierarchy from the current directory for a project .ackrc and loads its options. The project-source option blocklist in App::Ack::ConfigLoader does not include --files-from, so a project .ackrc can set it to a path whose listed files ack then reads and searches. Version 3.10.0 added --follow to the blocklist; --files-from remains accepted.

A project .ackrc committed to an untrusted repository can make ack read files outside the project and print their matching lines.
Published: 2026-07-08
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

App::Ack, a Perl search tool that loads project configuration from a .ackrc file in the current directory tree, allows the --files-from option to be specified in that configuration. Because the configuration blocklist does not exclude this option, an attacker can place a malicious .ackrc that points to any file the user can read. The tool will then read and expose the contents or matched lines of that file, enabling arbitrary file read on the system. The defect is captured in CVSS score 7.5, indicating high severity.

Affected Systems

Vulnerability affects the PETDANCE platform product App::Ack up to version 3.10.0. The patch release after 3.10.0 adds the --follow parameter to the blocklist, but --files-from remains accepted, so an update that blocks this option is required for protection.

Risk and Exploitability

The EPSS score is below 1%, showing a very low documented probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog, and no known public exploits exist. The likely attack vector is local execution of ack with a malicious .ackrc, wherein an attacker must influence the working directory or supply a repository that contains a malicious .ackrc. Remote exploitation would need an additional vector to get the target to run ack in a compromised configuration. Overall risk remains moderate, yet the high severity warrants timely remediation.

Generated by OpenCVE AI on July 29, 2026 at 14:06 UTC.

Remediation

Vendor Solution

Upgrade to a future ack release.


Vendor Workaround

Run ack with --noenv, or avoid running ack in a directory tree that contains an untrusted .ackrc.


OpenCVE Recommended Actions

  • Upgrade App::Ack to a version newer than 3.10.0.
  • Run ack with the --noenv flag to prevent loading project .ackrc files.
  • Avoid executing ack in directories that may contain untrusted .ackrc files, ensuring the repository is trusted before running the tool.

Generated by OpenCVE AI on July 29, 2026 at 14:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Petdance
Petdance app::ack
Vendors & Products Petdance
Petdance app::ack

Wed, 08 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc. ack searches up the directory hierarchy from the current directory for a project .ackrc and loads its options. The project-source option blocklist in App::Ack::ConfigLoader does not include --files-from, so a project .ackrc can set it to a path whose listed files ack then reads and searches. Version 3.10.0 added --follow to the blocklist; --files-from remains accepted. A project .ackrc committed to an untrusted repository can make ack read files outside the project and print their matching lines.
Title App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc
Weaknesses CWE-426
CWE-73
References

Subscriptions

Petdance App::ack
cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-07-08T17:31:32.120Z

Reserved: 2026-05-27T17:50:04.538Z

Link: CVE-2026-49145

cve-icon Vulnrichment

Updated: 2026-07-08T17:31:32.120Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T14:15:03Z

Weaknesses
  • CWE-426

    Untrusted Search Path

  • CWE-73

    External Control of File Name or Path