PatchSiren cyber security CVE debrief
CVE-2017-20285 TINITA CVE debrief
CVE-2017-20285 is a vulnerability in YAML versions before 1.30 for Perl, which allows a loaded document to trigger the DESTROY method of arbitrary classes. This can lead to deletion of a directory tree when File::Temp::Dir from core Perl is used. The vulnerability exists due to the way YAML documents are processed, allowing an attacker to manipulate the DESTROY method of arbitrary classes. Defenders and developers should assess exposure and prioritize remediation to prevent potential directory tree deletion.
- Vendor
- TINITA
- Product
- YAML
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-05
- Original CVE updated
- 2026-10-05
- Advisory published
- 2026-10-05
- Advisory updated
- 2026-10-05
Who should care
Defenders and developers using YAML versions before 1.30 for Perl should assess exposure and prioritize remediation to prevent potential directory tree deletion. This includes reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should also plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Why it matters
CVE-2017-20285 is a vulnerability in YAML versions before 1.30 for Perl that allows arbitrary class DESTROY method invocation, potentially leading to directory tree deletion. Defenders and developers should assess exposure and prioritize remediation.
- Deletion of directory trees when File::Temp::Dir is used
- Verification of YAML version in use
- Assessment of exposure in environments using YAML versions before 1.30 for Perl
Technical summary
The vulnerability exists in YAML versions before 1.30 for Perl. A loaded YAML document can trigger the DESTROY method of arbitrary classes. This can lead to deletion of a directory tree when File::Temp::Dir from core Perl is used. The vulnerability is particularly concerning when File::Temp::Dir from core Perl is used, as it can lead to deletion of a directory tree. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope. There is no evidence of in-the-wild exploitation, but defenders should verify
Defensive priority
Assess exposure and prioritize remediation for systems using YAML versions before 1.30 for Perl.
Recommended defensive actions
- Assess exposure of YAML versions before 1.30 for Perl in your environment
- Prioritize remediation for systems using YAML versions before 1.30 for Perl
- Verify if File::Temp::Dir from core Perl is used in your environment
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability is triggered when a loaded YAML document causes the DESTROY method to be called on an object of an arbitrary class. With File::Temp::Dir from core Perl, this can delete a directory tree specified in the document. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope. The vulnerability is particularly concerning when File::Temp::Dir from core Perl is used, as it can lead to deletion of a directory tree. There is no evidence of in-the-wild exploitation, but defenders should verify
Sources and references
Verified primary and authoritative sources
-
CVE-2017-20285 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-20285
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-20285 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-20285
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/ingydotnet/yaml-pm/commit/471314bbdcbd62077eea32755929122aa8bd00a3.patch
9b29abf9-4ab0-4765-b253-1875cd9b441e
-
Source reference
Unverified legacy reference
URL: https://github.com/ingydotnet/yaml-pm/commit/7736f38bd02e4f9f77d5468721e3be3d7b34a8ec.patch
9b29abf9-4ab0-4765-b253-1875cd9b441e
-
Source reference
Unverified legacy reference
URL: https://github.com/ingydotnet/yaml-pm/issues/176
9b29abf9-4ab0-4765-b253-1875cd9b441e
-
Source reference
Unverified legacy reference
URL: https://metacpan.org/release/TINITA/YAML-1.30/changes
9b29abf9-4ab0-4765-b253-1875cd9b441e
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.