OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2019-25777

HIGH · CVSS 7.3 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

YAML versions prior to 1.27_001 for Perl are vulnerable to arbitrary code execution due to insufficient restrictions on loaded perl/glob documents, which can manipulate package variables. Attackers can exploit this vulnerability by supplying crafted documents that enable code loading, allowing them to execute arbitrary Perl code through subsequent Load() calls. Organizations using affected versions of YAML in their Perl applications should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2019-25777
Severity
HIGH
CVSS
7.3
EPSS
0.22%

Original NVD Description

YAML versions before 1.27_001 for Perl allow a loaded perl/glob document to replace any package variable, which can lead to arbitrary code execution. A perl/glob document names a package and a symbol, and supplies the value assigned to it. Nothing restricts the name, so the target can be @INC or YAML's own load options. A perl/glob document that sets $YAML::LoadCode or $YAML::UseCode turns on code loading, which is off by default, for every later Load() in the process. A perl/code document is then passed to a string eval, so an attacker who supplies two documents to separate Load() calls in one process can execute arbitrary Perl code.