Description
Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call.

The Pluggable subclass reads credential_source.executable.command from the credentials JSON and runs it as `system($command)`, a single argument call that passes the whole string to /bin/sh -c. The executable's environment_variables map from the same JSON is copied into %ENV first. No opt-in gate guards the call. make_creds selects the Pluggable subclass whenever credential_source.executable is present, so the path is reached from the standard Application Default Credentials flow, including a "type": "external_account" configuration read from the file named by GOOGLE_APPLICATION_CREDENTIALS. Configurations without credential_source.executable do not select this subclass and do not reach the call.

Any caller that builds credentials from a configuration it does not fully control runs the embedded command with the privileges of the application process.
Published: 2026-08-04
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a malicious or compromised credentials file to execute arbitrary commands on the host system with the privileges of the application process. The Pluggable subclass of the module reads the field credential_source.executable.command from the JSON and performs a single-argument system call through /bin/sh -c without any gating or validation. As a result, any user who can supply or modify the credentials JSON can inject code that will run as the process that loads the credentials.

Affected Systems

Versions of the Perl module Google::Auth from the package CJCOLLIER released prior to 0.06 are affected. Any application that relies on the Application Default Credentials flow, particularly those that consume a credentials file named by the environment variable GOOGLE_APPLICATION_CREDENTIALS and use a "type": "external_account" configuration, will hit the vulnerable code path. No specific minor versions are enumerated; all pre‑0.06 releases are included.

Risk and Exploitability

The flaw is a classic command injection (CWE‑78) that escalates privileges where the credentials file is writable or under an attacker’s control (CWE‑829). The absence of a verification gate means the attack is straight‑forward: write the credentials JSON to trigger an arbitrary command in the process context. The affected module is not listed in CISA KEV and the EPSS score is unavailable, but the impact is high because any attacker who can tamper with the credentials file can execute code and compromise the host, leading to data loss, credential theft, and lateral movement.

Generated by OpenCVE AI on August 4, 2026 at 22:40 UTC.

Remediation

Vendor Solution

Upgrade to Google-Auth 0.06 or later, which throws unless the environment variable GOOGLE_EXTERNAL_ACCOUNT_ALLOW_EXECUTABLES is set to 1.


Vendor Workaround

For deployments that cannot upgrade to 0.06, apply the upstream fix commit, or ensure that every credentials configuration reaching the Application Default Credentials flow comes from a trusted source.


OpenCVE Recommended Actions

  • Upgrade to Google-Auth 0.06 or later, which throws unless the environment variable GOOGLE_EXTERNAL_ACCOUNT_ALLOW_EXECUTABLES is set to 1.
  • If an upgrade is not possible, apply the upstream fix commit that removes the ungated system call.
  • When using a legacy version, set the environment variable GOOGLE_EXTERNAL_ACCOUNT_ALLOW_EXECUTABLES to 1 only if the execution path is required and trusted.
  • Ensure the file pointed to by GOOGLE_APPLICATION_CREDENTIALS is owned by a trusted account and has permissions that prevent unauthorized modifications.

Generated by OpenCVE AI on August 4, 2026 at 22:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call. The Pluggable subclass reads credential_source.executable.command from the credentials JSON and runs it as `system($command)`, a single argument call that passes the whole string to /bin/sh -c. The executable's environment_variables map from the same JSON is copied into %ENV first. No opt-in gate guards the call. make_creds selects the Pluggable subclass whenever credential_source.executable is present, so the path is reached from the standard Application Default Credentials flow, including a "type": "external_account" configuration read from the file named by GOOGLE_APPLICATION_CREDENTIALS. Configurations without credential_source.executable do not select this subclass and do not reach the call. Any caller that builds credentials from a configuration it does not fully control runs the embedded command with the privileges of the application process.
Title Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call
Weaknesses CWE-78
CWE-829
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-08-04T22:24:41.647Z

Reserved: 2026-07-28T08:28:27.249Z

Link: CVE-2026-66902

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T22:45:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere