Did you at least contact Lincoln Stein (the author) about this?
In reply to Re: A serious security problem with CGI.pm 3.01? by rrwo in thread A serious security problem with CGI.pm 3.01? by tachyon