CVE-2019-25777
Received Received - Intake

Arbitrary Code Execution in YAML Perl Module

Vulnerability report for CVE-2019-25777, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: CPANSec

Description

YAML versions before 1.27_001 for Perl allow a loaded perl/glob document to replace any package variable, which can lead to arbitrary code execution. A perl/glob document names a package and a symbol, and supplies the value assigned to it. Nothing restricts the name, so the target can be @INC or YAML's own load options. A perl/glob document that sets $YAML::LoadCode or $YAML::UseCode turns on code loading, which is off by default, for every later Load() in the process. A perl/code document is then passed to a string eval, so an attacker who supplies two documents to separate Load() calls in one process can execute arbitrary Perl code.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ingydotnet yaml to 1.27_001 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
CWE-914 The product does not properly restrict reading from or writing to dynamically-identified variables.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in YAML versions before 1.27_001 for Perl allows a loaded perl/glob document to replace any package variable, potentially leading to arbitrary code execution. The issue arises because a perl/glob document can name a package and symbol, including critical variables like @INC or YAML's own load options, without restriction.

Detection Guidance

To detect this vulnerability, check if your system uses YAML versions before 1.27_001 for Perl. Inspect Perl modules and YAML library versions installed. Look for usage of $YAML::LoadCode or $YAML::UseCode flags in codebases that process YAML files.

Impact Analysis

An attacker could exploit this by supplying two documents to separate Load() calls in one process. If $YAML::LoadCode or $YAML::UseCode is set to true, code loading is enabled, and a perl/code document is passed to a string eval, allowing arbitrary Perl code execution.

Compliance Impact

This vulnerability allows arbitrary code execution through YAML parsing, which could lead to unauthorized data access, modification, or exfiltration. Such risks may violate GDPR's integrity and confidentiality requirements or HIPAA's safeguards for protected health information if exploited in systems handling regulated data.

Mitigation Strategies

Update the YAML Perl module to version 1.27_001 or later. Review and remove any instances of $YAML::LoadCode or $YAML::UseCode flags in your code. Ensure glob loading is disabled by default in YAML processing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2019-25777. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart