CYBERSECURITYTRACKER
TRACKING7,353 stories in this site build1,545 vulnerability news stories in this site build
Permanent story citation

CVE-2026-93712: Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8098

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-93712: Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler

Dancer2 versions 2.1.0 through 2.1.x contain a path traversal vulnerability that allows serving files outside the designated public directory via relative path segments in the File route handler. The vulnerability is resolved in version 2.2.0.

Why it matters: Developers and operators running Dancer2 2.1.x on publicly accessible systems risk unauthorized file disclosure, including sensitive application and system files, and should upgrade immediately to version 2.2.0 or later.

VendorsGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary