VYPR

YAML

by YAML

CVEs (1)

  • CVE-2019-25777Oct 5, 2026
    risk 0.00cvss —epss —

    YAML versions before 1.27_001 for Perl allow a loaded perl/glob document to replace any package variable, which can lead to arbitrary code execution. A perl/glob document names a package and a symbol, and supplies the value assigned to it. Nothing restricts the name, so the…