CVE-2025-30672

Source
https://cve.org/CVERecord?id=CVE-2025-30672
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-30672.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-30672
Published
2025-04-01T01:51:08.494Z
Modified
2026-07-15T01:48:51.633553361Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Mite for Perl generates code with an untrusted search path vulnerability
Details

Mite for Perl before 0.013000 generates code with the current working directory ('.') added to the @INC path similar to CVE-2016-1238.

If an attacker can place a malicious file in current working directory, it may be loaded instead of the intended file, potentially leading to arbitrary code execution.

This affects the Mite distribution itself, and other distributions that contain code generated by Mite.

Database specific
{
    "cna_assigner": "CPANSec",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30672.json",
    "cwe_ids": [
        "CWE-427"
    ]
}
References

Affected packages

Git / github.com/tobyink/p5-mite

Affected ranges

Type
GIT
Repo
https://github.com/tobyink/p5-mite
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.013000"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.001000
0.001001
0.001002
0.001003
0.001004
0.001005
0.001006
0.001007
0.001008
0.001009
0.001010
0.001011
0.001012
0.001013
0.002000
0.002001
0.002002
0.002003
0.002004
0.003000
0.003001
0.004000
0.005000
0.005001
0.005002
0.005003
0.005004
0.006000
0.006001
0.006002
0.006003
0.006004
0.006005
0.006006
0.006007
0.006008
0.006009
0.006010
0.006011
0.006012
0.006013
0.007000
0.007001
0.007002
0.007003
0.007004
0.007005
0.007006
0.008000
0.008001
0.008002
0.008003
0.009000
0.009001
0.009002
0.009003
0.010000
0.010001
0.010002
0.010003
0.010004
0.010005
0.010006
0.010007
0.010008
0.011000
0.012000
Acme-Mitey-Cards-0.*
Acme-Mitey-Cards-0.001
Acme-Mitey-Cards-0.002
Acme-Mitey-Cards-0.003
Acme-Mitey-Cards-0.004
Acme-Mitey-Cards-0.005
Acme-Mitey-Cards-0.006
Acme-Mitey-Cards-0.007
Acme-Mitey-Cards-0.008
Acme-Mitey-Cards-0.009
Acme-Mitey-Cards-0.010
Acme-Mitey-Cards-0.011
Acme-Mitey-Cards-0.013
Acme-Mitey-Cards-0.014
Acme-Mitey-Cards-0.014#
v0.*
v0.0.2
v0.0.3
v0.0.4
v0.0.5
v0.0.7
v0.0.8
v0.0.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-30672.json"