FixVibe

critical

Command Injection and File Overwrite in Perl GD Library (CVE-2026-11526)

Perl GD versions before 2.86 are affected by CVE-2026-11526 when untrusted pathname strings reach filename-accepting GD::Image constructors. FixVibe GitHub repo scans flag affected GD versions in CPAN dependency files.

CVE-2026-11526CWE-73CWE-78

Impact

Applications that depend on Perl GD before 2.86 may be affected by CVE-2026-11526 when application code passes untrusted strings as pathnames into filename-accepting GD::Image constructors [S1][S2]. Treat repository evidence as dependency upgrade evidence; runtime command execution or file overwrite depends on how the application handles filenames and which GD runtime is deployed.

Root Cause

GD::Image::_make_filehandle used Perl's two-argument open() for filename arguments in affected versions. CPANSec and NVD describe that filenames using pipe or redirect syntax can be interpreted as command or file redirection by Perl rather than opened as ordinary paths [S1][S2]. GD 2.86 changes the open behavior, and the upstream changelog records the CVE fix [S3][S4].

Covered by FixVibe

FixVibe's GitHub repo scans flag CPAN dependency files such as cpanfile, cpanfile.snapshot, META.json, and Makefile.PL that resolve GD to a version before 2.86 [S1][S3], with the file, version and fixed version.

Fix

Upgrade GD to 2.86 or later [S1][S3]. Regenerate cpanfile.snapshot or the CPAN metadata that controls deployment, rebuild any Perl app image, worker, CI cache, devcontainer, or host bundle that installs CPAN modules, and verify the deployed runtime reports a fixed GD version. Review filename-accepting GD::Image call sites so untrusted filenames are rejected, opened as filehandles before reaching GD, or handled through in-memory *Data APIs where appropriate.