File::Find::Rule through 0.34 for Perl is vulnerable to Arbitrary Code Execution when `grep()` encounters a crafted file name
Published Jun 5, 2025
8.8
HIGHCVSS 3.1
EPSS 0.80%
Description
File::Find::Rule through 0.34 for Perl is vulnerable to Arbitrary Code Execution when `grep()` encounters a crafted filename.
A file handle is opened with the 2 argument form of `open()` allowing an attacker controlled filename to provide the MODE parameter to `open()`, turning the filename into a command to be executed.
Example:
$ mkdir /tmp/poc; echo > "/tmp/poc/|id" $ perl -MFile::Find::Rule \ -E 'File::Find::Rule->grep("foo")->in("/tmp/poc")' uid=1000(user) gid=1000(user) groups=1000(user),100(users)
Affected products
-
- Version 0StatusaffectedConstraints<=0.34
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Rclamp | File::Find::Rule | unaffected |
|
No data.
No data.
Red Hat Enterprise Linux 7 Extended Lifecycle Support
perl-File-Find-Rule-0:0.33-5.el7_9.1
Fixed · RHSA-2025:9741
Red Hat Enterprise Linux 7 Extended Lifecycle Support
perl-File-Find-Rule-Perl-0:1.13-2.el7_9.1
Fixed · RHSA-2025:9740
Red Hat Enterprise Linux 8
perl-File-Find-Rule-0:0.34-9.el8_10
Fixed · RHSA-2025:9605
Red Hat Enterprise Linux 9
perl-File-Find-Rule-0:0.34-19.1.el9_6
Fixed · RHSA-2025:9517
Red Hat Enterprise Linux 9.4 Extended Update Support
perl-File-Find-Rule-0:0.34-19.el9_4.1
Fixed · RHSA-2025:9658
Red Hat Enterprise Linux 6
perl-File-Find-Rule
Out of support scope
Red Hat Enterprise Linux 6
perl-File-Find-Rule-Perl
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | perl-File-Find-Rule-0:0.33-5.el7_9.1 | Fixed | RHSA-2025:9741 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | perl-File-Find-Rule-Perl-0:1.13-2.el7_9.1 | Fixed | RHSA-2025:9740 |
| Red Hat Enterprise Linux 8 | perl-File-Find-Rule-0:0.34-9.el8_10 | Fixed | RHSA-2025:9605 |
| Red Hat Enterprise Linux 9 | perl-File-Find-Rule-0:0.34-19.1.el9_6 | Fixed | RHSA-2025:9517 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | perl-File-Find-Rule-0:0.34-19.el9_4.1 | Fixed | RHSA-2025:9658 |
| Red Hat Enterprise Linux 6 | perl-File-Find-Rule | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | perl-File-Find-Rule-Perl | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Users should update to a fixed version such as 0.35 or later, or apply the patch provided in the references section, or use a patched version provided by their OS distribution
Red Hat statement
This vulnerability marked as Important rather than Moderate because it enables arbitrary code execution (ACE) through a common and trusted interface—filename handling. Specifically, the use of Perl’s two-argument open() within the grep() method allows attacker-controlled filenames to be interpreted as shell commands when prefixed with special characters like |. Since File::Find::Rule is often used in automation scripts, system utilities, and recursive file operations, this flaw transforms a seemingly benign filename input into an execution vector, violating a core security boundary between data and code. The vulnerability does not require elevated privileges or complex exploitation chains; a single crafted filename is enough to trigger shell execution, making the flaw exploitable in real-world scenarios such as CI/CD pipelines or file indexing systems.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Jun 5, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.80% (0.00800) | 54.97th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.74% (0.00736) | 49.46th | v5 (v2026.06.15) |
| Jun 6, 2025 | 0.05% (0.00051) | 15.62th | v4 (v2025.03.14) |
References (12)
- http://www.openwall.com/lists/oss-security/2025/06/05/4
- http://www.openwall.com/lists/oss-security/2025/06/06/1
- http://www.openwall.com/lists/oss-security/2025/06/06/3
- https://access.redhat.com/security/cve/CVE-2011-10007 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2370424 Issue Tracking
- https://github.com/richardc/perl-file-find-rule/commit/df58128bcee4c1da78c34d7f3fe1357e575ad56f.patch patch
- https://github.com/richardc/perl-file-find-rule/pull/4 exploitissue-tracking
- https://lists.debian.org/debian-lts-announce/2025/06/msg00006.html
- https://metacpan.org/release/RCLAMP/File-Find-Rule-0.34/source/lib/File/Find/Rule.pm#L423
- https://nvd.nist.gov/vuln/detail/CVE-2011-10007
- https://rt.cpan.org/Public/Bug/Display.html?id=64504 issue-trackingexploit
- https://www.cve.org/CVERecord?id=CVE-2011-10007
Change history (0)
No recorded changes yet.