As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-93709: Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage handler
Dancer2, a Perl web framework, contains a vulnerability in its AutoPage handler that allows serving layout files as pages when path variants bypass the guard mechanism. Affected versions are before 2.2.0. The issue enables unintended access to protected template content through alternate path spellings.
Why it matters: Developers using Dancer2 before version 2.2.0 should upgrade immediately to prevent attackers from accessing layout files and potentially sensitive templating logic through path manipulation.
- Source published
- First seen by Cybersecurity Tracker