CVE-2026-66902: Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call
Google::Auth versions before 0.06 for Perl run a command named in an externalaccount credentials JSON via an ungated system call.
The Pluggable subclass reads credentialsource.executable.command from the credentials JSON and runs it as system($command), a single argument call that passes the whole string to /bin/sh -c. The executable's environmentvariables map from the same JSON is copied into %ENV first. No opt-in gate guards the call. makecreds selects the Pluggable subclass whenever credentialsource.executable is present, so the path is reached from the standard Application Default Credentials flow, including a "type": "externalaccount" configuration read from the file named by GOOGLEAPPLICATIONCREDENTIALS. Configurations without credentialsource.executable do not select this subclass and do not reach the call.
Any caller that builds credentials from a configuration it does not fully control runs the embedded command with the privileges of the application process.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google::Auth (Perl)to a version that resolves this vulnerability.Fixed in 0.06 - Configuration
Ensure GOOGLE_EXTERNAL_ACCOUNT_ALLOW_EXECUTABLES is not set to 1 (leave unset or set to 0) so Google::Auth 0.06+ does not allow execution of credential_source.executable.command from external_account credentials JSON.
Google::Auth (Perl) GOOGLE_EXTERNAL_ACCOUNT_ALLOW_EXECUTABLES = 0