Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2vrw-pcjq-fv9h

Опубликовано: 04 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 4.8
CVSS3: 6.5

Описание

If a malformed data is input to the affected product, a CSV file downloaded from the affected product may contain such malformed data. When a victim user download and open such a CSV file, the embedded code may be executed in the user's environment. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well.

If a malformed data is input to the affected product, a CSV file downloaded from the affected product may contain such malformed data. When a victim user download and open such a CSV file, the embedded code may be executed in the user's environment. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well.

EPSS

Процентиль: 1%
0.00012
Низкий

4.8 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-1236

Связанные уязвимости

CVSS3: 6.5
ubuntu
4 дня назад

If a malformed data is input to the affected product, a CSV file downloaded from the affected product may contain such malformed data. When a victim user download and open such a CSV file, the embedded code may be executed in the user's environment. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well.

CVSS3: 6.5
nvd
4 дня назад

If a malformed data is input to the affected product, a CSV file downloaded from the affected product may contain such malformed data. When a victim user download and open such a CSV file, the embedded code may be executed in the user's environment. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well.

CVSS3: 6.5
debian
4 дня назад

If a malformed data is input to the affected product, a CSV file downl ...

EPSS

Процентиль: 1%
0.00012
Низкий

4.8 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-1236