{"id":"CVE-2026-75031","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-75031","summary":"In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the \n“quick question” admin feature. In default installations arbitrary Perl…","details":"In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the \n“quick question” admin feature. In default installations arbitrary Perl \ncode can be injected and executed server-side by unauthenticated users. \nThe Perl code normally runs within a Safe container which limits the \nscope of what it can do, unless the non-default AllowGlobal directive is\n configured for the catalog being accessed.CTOR]","published":"2026-09-18T16:17:09.043","modified":"2026-09-18T16:17:09.043","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/interchange/interchange/commit/65b6ea9d3761dd1fd2071c962819562afa335e4e","label":"interchange/interchange@65b6ea9"},"references":[{"type":"WEB","url":"https://github.com/interchange/interchange/commit/65b6ea9d3761dd1fd2071c962819562afa335e4e"},{"type":"WEB","url":"https://www.interchangecommerce.org/i/dev/news?mv_arg=00071"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-18T16:17:09.043"}}