Imperva discloses a critical vulnerability (CVSS 7.7) in Perforce’s P4 protocol affecting client versions before Helix Core 2025.2 Patch 2. The flaw stems from missing server response validation on the client, letting attackers inject malicious instructions into configuration files via the P4LOGINSSO environment variable to achieve arbitrary code execution.