PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-20285 TINITA CVE debrief

CVE-2017-20285 is a vulnerability in YAML versions before 1.30 for Perl, which allows a loaded document to trigger the DESTROY method of arbitrary classes. This can lead to deletion of a directory tree when File::Temp::Dir from core Perl is used. The vulnerability exists due to the way YAML documents are processed, allowing an attacker to manipulate the DESTROY method of arbitrary classes. Defenders and developers should assess exposure and prioritize remediation to prevent potential directory tree deletion.

Vendor
TINITA
Product
YAML
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-05
Original CVE updated
2026-10-05
Advisory published
2026-10-05
Advisory updated
2026-10-05

Who should care

Defenders and developers using YAML versions before 1.30 for Perl should assess exposure and prioritize remediation to prevent potential directory tree deletion. This includes reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should also plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Why it matters

CVE-2017-20285 is a vulnerability in YAML versions before 1.30 for Perl that allows arbitrary class DESTROY method invocation, potentially leading to directory tree deletion. Defenders and developers should assess exposure and prioritize remediation.

  • Deletion of directory trees when File::Temp::Dir is used
  • Verification of YAML version in use
  • Assessment of exposure in environments using YAML versions before 1.30 for Perl

Technical summary

The vulnerability exists in YAML versions before 1.30 for Perl. A loaded YAML document can trigger the DESTROY method of arbitrary classes. This can lead to deletion of a directory tree when File::Temp::Dir from core Perl is used. The vulnerability is particularly concerning when File::Temp::Dir from core Perl is used, as it can lead to deletion of a directory tree. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope. There is no evidence of in-the-wild exploitation, but defenders should verify

Defensive priority

Assess exposure and prioritize remediation for systems using YAML versions before 1.30 for Perl.

Recommended defensive actions

  • Assess exposure of YAML versions before 1.30 for Perl in your environment
  • Prioritize remediation for systems using YAML versions before 1.30 for Perl
  • Verify if File::Temp::Dir from core Perl is used in your environment
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability is triggered when a loaded YAML document causes the DESTROY method to be called on an object of an arbitrary class. With File::Temp::Dir from core Perl, this can delete a directory tree specified in the document. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope. The vulnerability is particularly concerning when File::Temp::Dir from core Perl is used, as it can lead to deletion of a directory tree. There is no evidence of in-the-wild exploitation, but defenders should verify

Sources and references

Verified primary and authoritative sources

  • CVE-2017-20285 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-20285

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-20285 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-20285

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ingydotnet/yaml-pm/commit/471314bbdcbd62077eea32755929122aa8bd00a3.patch

    9b29abf9-4ab0-4765-b253-1875cd9b441e

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ingydotnet/yaml-pm/commit/7736f38bd02e4f9f77d5468721e3be3d7b34a8ec.patch

    9b29abf9-4ab0-4765-b253-1875cd9b441e

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ingydotnet/yaml-pm/issues/176

    9b29abf9-4ab0-4765-b253-1875cd9b441e

  • Source reference

    Unverified legacy reference

    URL: https://metacpan.org/release/TINITA/YAML-1.30/changes

    9b29abf9-4ab0-4765-b253-1875cd9b441e

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.