Description
DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM.

DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. require treats a path-shaped string as a literal filename and does not consult @INC, so the attribute chooses the file that Perl loads and runs.

The MLDBM::Serializer:: prefix that DBD::DBM prepends to dbm_mldbm is not a boundary: only the :: separators are rewritten to /, so a value containing / traverses out of the serializer directory. The value is also assigned to $MLDBM::Serializer, which MLDBM requires the same way when it ties the table.

A caller that lets an untrusted party influence either attribute, for example through a DSN fragment or a parameter that selects a storage backend, runs the file-scope code of whatever module the value names.

For example,

my $dsn = "dbi:DBM:f_dir=/var/db;dbm_type=../../Untrusted.pm"
my $dbh = DBI->connect( $dsn );

Note that DBD::Gofer forwards connect attributes to the server side, and DBI::ProxyServer checks only that a DSN starts with a driver prefix.
Published: 2026-09-19
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary Code Execution
Action: Immediate Patch
AI Analysis

Impact

Prior to version 1.653, Perl's DBI library allows an attacker to load arbitrary modules via the unvalidated dbm_type and dbm_mldbm connect attributes in the DBD::DBM driver, because these values are passed directly to Perl's require without any sanitization. An attacker can supply a path or module name that points to any file, causing the application to execute code during the database connection establishment. The vulnerability is classified as CWE‑470 and can lead to arbitrary code execution in the application's context.

Affected Systems

This issue affects the Perl DBI module (specifically the DBD::DBM driver) for all releases prior to 1.653. Operating systems or distributions that ship this library via CPAN or other package managers must upgrade the DBI package to 1.653 or later to eliminate the flaw.

Risk and Exploitability

Based on the description, the vulnerability can be exploited when an application constructs a database connection request that includes untrusted values for the dbm_type or dbm_mldbm attributes. Those attributes are passed directly to Perl's require, so an attacker can supply a path or module name that points to arbitrary Perl code, which will be loaded during connection establishment. This results in arbitrary code execution within the application’s process. The description does not specify whether network access, local privilege, or other preconditions are required, so the potential scope and conditions remain uncertain. The CVSS score of 9.8 indicates a critical severity. The EPSS value is not available, and the vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 20, 2026 at 02:29 UTC.

Remediation

Vendor Solution

Upgrade to DBI version 1.653 or later, or apply the upstream patch.


OpenCVE Recommended Actions

  • Upgrade the Perl DBI library to version 1.653 or later.
  • If immediate upgrade is not possible, apply the upstream patch (commit 315c6ce703b8b3cbe9188062d9ec80730293554a.patch).
  • Ensure that applications do not set the dbm_type or dbm_mldbm attributes from untrusted input, or sanitize these values before use to prevent loading arbitrary modules.

Generated by OpenCVE AI on September 20, 2026 at 02:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4798-1 libdbi-perl security update
History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Perl5-dbi
Perl5-dbi dbi
Vendors & Products Perl5-dbi
Perl5-dbi dbi

Sat, 19 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
References

Sat, 19 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. require treats a path-shaped string as a literal filename and does not consult @INC, so the attribute chooses the file that Perl loads and runs. The MLDBM::Serializer:: prefix that DBD::DBM prepends to dbm_mldbm is not a boundary: only the :: separators are rewritten to /, so a value containing / traverses out of the serializer directory. The value is also assigned to $MLDBM::Serializer, which MLDBM requires the same way when it ties the table. A caller that lets an untrusted party influence either attribute, for example through a DSN fragment or a parameter that selects a storage backend, runs the file-scope code of whatever module the value names. For example, my $dsn = "dbi:DBM:f_dir=/var/db;dbm_type=../../Untrusted.pm" my $dbh = DBI->connect( $dsn ); Note that DBD::Gofer forwards connect attributes to the server side, and DBI::ProxyServer checks only that a DSN starts with a driver prefix.
Title DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM
Weaknesses CWE-470
References

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-09-20T00:05:29.533Z

Reserved: 2026-08-22T00:39:23.300Z

Link: CVE-2026-78030

cve-icon Vulnrichment

Updated: 2026-09-20T00:05:20.327Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T11:16:37.667

Modified: 2026-09-22T19:07:00.983

Link: CVE-2026-78030

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:30:17Z

Weaknesses
  • CWE-470

    Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')