A vulnerability classified as critical was found in Data::MuForm::Localizer up to 0.05. This impacts the function Data::MuForm::Localizer::load_lexicon/Data::MuForm::Localizer::extract_header_msgstr of the file Localizer.pm of the component Message Catalog Loader. Executing a manipulation of the argument lang can lead to os command injection.

This vulnerability is tracked as CVE-2026-13048. The attack can be launched remotely. No exploit exists.