CVE-2026-66902: Google::Auth Perl Library RCE via Credential JSON Injection
ID: 256de1f0-20e6-5ce7-8c31-d225dec77e9d
STIX ID: report--256de1f0-20e6-5ce7-8c31-d225dec77e9d
Feed Name: CosmicBytez Labs
Threat Score
A critical command-injection vulnerability (CVE-2026-66902, CVSS 9.8) in Google::Auth (Perl) < 0.06 allows unauthenticated remote code execution by passing credential_source.executable.command into Perl's single-argument system(); the report details affected versions, attack vectors (malicious credentials, SSRF/path traversal, CI/CD injection, supply chain), impact, detection indicators, and recommends upgrading to 0.06 and hardening credential files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
