Security Advisories (14)
Mojo::DOM did not correctly parse <script> tags.
Small sessions could be used as part of a brute-force attack to decode the session secret.
A bug in format detection can potentially be exploited for a DoS attack.
Mojo::UserAgent was not checking peer SSL certificates by default.
GET requests with embedded backslashes can be used to access local files on Windows hosts
Mojo::UserAgent::CookieJar leaks old cookies because of the missing host_only flag on empty domain.
Directory traversal on Windows
Context sensitivity of method param could lead to parameter injection attacks.
Directory traversal vulnerability in Path.pm in Mojolicious before 1.16 allows remote attackers to read arbitrary files via a %2f..%2f (encoded slash dot dot slash) in a URI.
Mojolicious before 0.999927 does not properly implement HMAC-MD5 checksums, which has unspecified impact and remote attack vectors.
Commands.pm in Mojolicious before 0.999928 does not properly perform CGI environment detection, which has unspecified impact and remote attack vectors.
- https://github.com/kraih/mojo/commit/b3a1fb453eda447c0bb082cd9eed81bb75a7564a
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=622952
- https://github.com/kraih/mojo/commit/aa7c8da54b1ebd4ccb64aa66dede7b7cdb381c44
- http://cpansearch.perl.org/src/KRAIH/Mojolicious-1.20/Changes
- http://www.debian.org/security/2011/dsa-2239
Cross-site scripting (XSS) vulnerability in the link_to helper in Mojolicious before 1.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- https://exchange.xforce.ibmcloud.com/vulnerabilities/67257
- https://www.debian.org/security/2011/dsa-2239
- https://github.com/mojolicious/mojo/commit/f6801ef7be8c78092e38f870b19fae3da0899d60
- http://cpansearch.perl.org/src/KRAIH/Mojolicious-1.20/Changes
- http://lists.fedoraproject.org/pipermail/package-announce/2011-May/060122.html
- http://www.securityfocus.com/bid/47713
Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder. The pure-Perl decode path (`_decode_value` dispatching to `_decode_array` and `_decode_object`) recurses with no depth limit, so a small deeply nested JSON document can consume excessive memory. This path is the default when Cpanel::JSON::XS is not installed or `MOJO_NO_JSON_XS=1` is set; the Cpanel::JSON::XS fast path is not affected. Any caller that decodes an untrusted JSON body, for example `Mojo::Message::json` reached through `$c->req->json`, can exhaust process memory and cause denial of service.
Mojolicious versions from 0.999922 for Perl uses a hard coded string, or the application's class name, as an HMAC session cookie secret by default. These predictable default secrets can be exploited by an attacker to forge session cookies. An attacker who knows or guesses the secret could compute valid HMAC signatures for the session cookie, allowing them to tamper with or hijack another user’s session.
- https://github.com/mojolicious/mojo/pull/1791
- https://github.com/mojolicious/mojo/pull/2200
- https://www.synacktiv.com/publications/baking-mojolicious-cookies
- https://medium.com/securing/baking-mojolicious-cookies-revisited-a-case-study-of-solving-security-problems-through-security-by-13da7c225802
- https://metacpan.org/release/SRI/Mojolicious-9.39/source/lib/Mojolicious.pm#L51
- https://github.com/hashcat/hashcat/pull/4090
- https://lists.debian.org/debian-perl/2025/05/msg00016.html
- https://lists.debian.org/debian-perl/2025/05/msg00017.html
- https://lists.debian.org/debian-perl/2025/05/msg00018.html
- https://github.com/mojolicious/mojo/pull/2252
- https://docs.mojolicious.org/Mojolicious/Guides/FAQ#What-does-Your-secret-passphrase-needs-to-be-changed-mean
NAME
Mojo::Stateful - Stateful Base Class
SYNOPSIS
use base 'Mojo::Stateful';
DESCRIPTION
Mojo::Stateful is an abstract base class for state keeping objects.
ATTRIBUTES
Mojo::Stateful implements the following attributes.
state_cb
my $cb = $stateful->state_cb;
$stateful = $stateful->state_cb(sub {...});
Callback that will be invoked whenever the state of this object changes.
METHODS
Mojo::Stateful inherits all methods from Mojo::Base and implements the following new ones.
done
$stateful = $stateful->done;
Shortcut for setting the current state to done.
error
my $error = $stateful->error;
$stateful = $stateful->error(500);
Shortcut for setting the current state to error.
has_error
my $has_error = $stateful->has_error;
Check if an error occured.
is_done
my $done = $stateful->is_done;
Check if the state machine is done.
is_finished
my $finished = $stateful->is_finished;
Check if the state machine is finished, this includes the states done, done_with_leftovers and error.
is_state
my $is_state = $stateful->is_state('writing');
my $is_state = $stateful->is_state(qw/error reading writing/);
Check if the state machine is currently in a specific state.
state
my $state = $stateful->state;
$stateful = $stateful->state('writing');
The current state.
SEE ALSO
Module Install Instructions
To install Mojolicious, copy and paste the appropriate command in to your terminal.
cpanm Mojolicious
perl -MCPAN -e shell
install Mojolicious
For more information on module installation, please visit the detailed CPAN module installation guide.