CVE-2025-40909 describes a race condition in Perl threads, specifically affecting versions 5.13.6 and later, where file operations may target unintended paths due to a temporary change in the process-wide current working directory during thread creation. This local vulnerability (CVSS 5.9 Medium) allows an attacker to potentially load malicious code or access sensitive files from unexpected locations. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.13.6, < 5.41.13CPE match | cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025perl: Perl threads have a working directory race condition where file operations may target unintended paths
May 30, 2025Perl threads have a working directory race condition where file operations may target unintended paths
May 13, 2025