Weaknesses of type CWE-1236

190 results

Neutralização inadequada de fórmulas em arquivos CSV

Ocorre quando um arquivo CSV exportado contém fórmulas (como =SUM(), @SUM() ou similar) que são interpretadas automaticamente por aplicações como Excel ou LibreOffice. Um atacante injeta fórmulas maliciosas nos dados, que executam comandos ou acessam recursos quando o arquivo é aberto, contornando a percepção do usuário de que está apenas lendo dados.

Example

Uma aplicação web exporta dados de usuários para CSV. Um atacante insere o nome '=cmd|' /c calc'!A1' em seu perfil. Quando um admin abre o CSV no Excel, a fórmula executa a calculadora ou outro comando sem avisar.

How to mitigate

Prefixe dados suspeitos com aspas simples (') ou espaço antes de exportar, ou converta as células para texto puro explicitamente. Alternativamente, use formatos como JSON ou XML e oriente os usuários a abrir CSVs com modo de segurança aumentado ou importadores que não interpretam fórmulas.

CVE-2025-67851MEDIUMMoodle: moodle: formula injection allows arbitrary formula execution via unescaped data exportEPSS 0.3%CVE-2023-25611MEDIUMA improper neutralization of formula elements in a CSV file vulnerability in Fortinet FortiAnalyzer 6.4.0 - 6.4.9, 7.0.0 - 7.0.5, and 7.2.0 EPSS 0.3%CVE-2026-76797MEDIUMMongoSQL Transition Readiness Tool Improper Neutralization of Formula Elements in Generated ReportsEPSS 0.3%CVE-2026-10248MEDIUMSourceCodester Pharmacy Sales and Inventory System Supplier Creation export create_supplier csv injectionEPSS 0.2%CVE-2024-28764MEDIUMIBM WebSphere Automation CSV injectionEPSS 0.2%CVE-2025-54752MEDIUMMultiple versions of PowerCMS improperly neutralize formula elements in a CSV file. If a product user creates a malformed entry and a victiEPSS 0.2%CVE-2025-52386MEDIUMCycloneDX Sunshine v0.9 is vulnerable to CSV Formula Injection via a crafted JSON fileEPSS 0.2%CVE-2025-1421LOWFormula injection in a CSV file in Proget MDMEPSS 0.2%CVE-2025-35033MEDIUMMedical Informatics Engineering Enterprise Health CSV injectionEPSS 0.2%CVE-2025-58855HIGHWordPress AP HoneyPot WordPress Plugin Plugin <= 1.4 - Cross Site Request Forgery (CSRF) VulnerabilityEPSS 0.2%CVE-2026-55452MEDIUMSnipe-IT: CSV formula injection in Activity Report exportEPSS 0.2%CVE-2026-24447MEDIUMIf a malformed data is input to the affected product, a CSV file downloaded from the affected product may contain such malformed data. When EPSS 0.2%CVE-2026-27644MEDIUMtraccar allows CSV formula injection via exported position dataEPSS 0.2%CVE-2025-6838MEDIUMBroken Link Notifier <= 1.3.0 - Authenticated (Contributor+) CSV InjectionEPSS 0.2%CVE-2023-37219HIGH Tadiran Telecom Composit - CWE-1236: Improper Neutralization of Formula Elements in a CSV FileEPSS 0.2%CVE-2025-11279MEDIUMAxosoft Scrum and Bug Tracking Add Work Item csv injectionEPSS 0.2%CVE-2025-61873LOWBest Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used.EPSS 0.2%CVE-2026-64955MEDIUMVelociraptor CSV Formula Injection in Export PipelineEPSS 0.2%CVE-2026-42267MEDIUMKimai: Formula Injection via tag names in XLSX exportEPSS 0.2%CVE-2026-79971MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper SanitizaEPSS 0.2%