A malicious server could potentially overwrite key files to cause a denial of service or, in some cases, gain privileges by modifying executable files.
A security hole has been discovered in Safe.pm. When a Safe compartment has already been used, there's no guarantee that it's safe any longer, because there's a way for code executed within the Safe compartment to alter its operation mask.