CVE-2026-93712: Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler
Dancer2 before 2.2.0 can serve files outside public_dir via relative path segments.
oss-security carries CVE-2026-93712, affecting the Perl web framework Dancer2 from version 2.1.0 before 2.2.0. The File route handler can serve files from outside the configured public_dir when a request uses relative path segments. Stig Palmquist posted the notice, pointing to the MetaCPAN distribution and the PerlDancer GitHub repository. The announcement does not say the flaw is being exploited.