Impact
Applications that depend on Perl GD before 2.86 may be affected by CVE-2026-11526 when application code passes untrusted strings as pathnames into filename-accepting GD::Image constructors [S1][S2]. Treat repository evidence as dependency upgrade evidence; runtime command execution or file overwrite depends on how the application handles filenames and which GD runtime is deployed.
Root Cause
GD::Image::_make_filehandle used Perl's two-argument open() for filename arguments in affected versions. CPANSec and NVD describe that filenames using pipe or redirect syntax can be interpreted as command or file redirection by Perl rather than opened as ordinary paths [S1][S2]. GD 2.86 changes the open behavior, and the upstream changelog records the CVE fix [S3][S4].
Covered by FixVibe
FixVibe's GitHub repo scans flag CPAN dependency files such as cpanfile, cpanfile.snapshot, META.json, and Makefile.PL that resolve GD to a version before 2.86 [S1][S3], with the file, version and fixed version.
Fix
Upgrade GD to 2.86 or later [S1][S3]. Regenerate cpanfile.snapshot or the CPAN metadata that controls deployment, rebuild any Perl app image, worker, CI cache, devcontainer, or host bundle that installs CPAN modules, and verify the deployed runtime reports a fixed GD version. Review filename-accepting GD::Image call sites so untrusted filenames are rejected, opened as filehandles before reaching GD, or handled through in-memory *Data APIs where appropriate.
