CVE-2026-48962: IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob
IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IO::Compssto a version that resolves this vulnerability.Fixed in 2.220 - Upgrade
Upgrade
IO::Compressto a version that resolves this vulnerability.Fixed in 2.220 - Compensating control
If upgrading is not immediately possible, do not pass attacker-controlled values as the output glob to File::GlobMapper; ensure the output glob string is strictly controlled/validated before it reaches _parseOutputGlob()/_getFiles().
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48962?
The severity of CVE-2026-48962 is rated as 30, indicating a critical risk of arbitrary code execution.
How do I fix CVE-2026-48962?
To fix CVE-2026-48962, upgrade to IO-Compress version 2.220 or later.
What software is affected by CVE-2026-48962?
CVE-2026-48962 affects IO::Compress versions prior to 2.220 for Perl.
What type of vulnerability is CVE-2026-48962?
CVE-2026-48962 is a vulnerability that allows for arbitrary code execution via an attacker-controlled output glob.
When was CVE-2026-48962 published?
CVE-2026-48962 was published on May 27, 2026.