Skip to main content.

Interchange News

  • Remote code execution vulnerability patched

    Posted on August 8, 2026 by Andrew Baerg

    A critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature. In default installations arbitrary Perl code can be injected and executed server-side by unauthenticated users. The Perl code normally runs within a Safe container which limits the scope of what it can do, unless the non-default AllowGlobal directive is configured for the catalog being accessed.

    We encourage immediate remediation for all Interchange deployments. The Interchange Git repository contains the fix, and you can apply it by patching or replacing the page file dist/lib/UI/pages/admin/quick_question.html with this hardened version.

News archive