CVE-2026-75031

Source
https://cve.org/CVERecord?id=CVE-2026-75031
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75031.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-75031
Published
2026-09-18T15:20:40Z
Modified
2026-09-20T11:47:12Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature. In default installations arbitrary Perl code can be injected and executed server-side by unauthenticated users. The Perl code normally runs within a Safe container which limits the scope of what it can do, unless the non-default AllowGlobal directive is configured for the catalog being accessed.CTOR]

Database specific
{
    "cna_assigner": "redhat-cnalr",
    "cwe_ids": [
        "CWE-94"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75031.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "*"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/interchange/interchange

Affected ranges

Type
GIT
Repo
https://github.com/interchange/interchange
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

Other
DEB_4_9_8_2
DEB_4_9_8_20030706_1
DEB_4_9_8_20030911_1
DEB_4_9_8_20031010_1
DEB_4_9_8_20031014_1
DEB_5_3_0_20051004_1
DEB_5_3_0_20051028_1
DEB_5_7_7_1
MV_4_5_0
PRE_REL_4_8_0
REL_4_5_6
REL_4_5_8
REL_4_6_1
REL_4_6_2
REL_4_6_3
REL_4_6_4
REL_4_7_6
REL_4_7_7
REL_4_9_1
REL_4_9_2
REL_4_9_4
REL_4_9_5
REL_4_9_6
REL_4_9_8
REL_4_9_9
REL_5_0_0
REL_5_0_0_RC1
REL_5_0_0_RC2
REL_5_3_2
REL_5_5_1
REL_5_5_2
REL_5_7_1
REL_5_7_2
REL_5_7_3
REL_5_7_4
REL_5_7_5
REL_5_7_7
REL_5_8_2
STABLE_4_6-root
STABLE_4_8-root
STABLE_5_0-root
STABLE_5_2-root
STABLE_5_4-root
STABLE_5_6-root

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75031.json"