As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-93712: Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler
Dancer2 versions 2.1.0 through 2.1.x contain a path traversal vulnerability that allows serving files outside the designated public directory via relative path segments in the File route handler. The vulnerability is resolved in version 2.2.0.
Why it matters: Developers and operators running Dancer2 2.1.x on publicly accessible systems risk unauthorized file disclosure, including sensitive application and system files, and should upgrade immediately to version 2.2.0 or later.
- Source published
- First seen by Cybersecurity Tracker