ΠΠΎΠ»ΠΈΡΠ΅ΡΡΠ²ΠΎ 3
ΠΠΎΠ»ΠΈΡΠ΅ΡΡΠ²ΠΎ 3
CVE-2026-56652
Dool in versions up to 1.3.8 is vulnerable to a CSV injection vulnerability when exporting data to a CSV file, as it fails to sanitize cell content beginning with special formula characters like =, +, -, or @. A local attacker can exploit this by running a process with a crafted name starting with =, which injects malicious formulas into the CSV output that execute when a victim opens the file in a spreadsheet application.Β The issue was addressed by pull request #117
CVE-2026-56652
Dool in versions up to 1.3.8 is vulnerable to a CSV injection vulnerab ...
GHSA-w3j2-f8wq-g63j
Dool in versions up to 1.3.8 is vulnerable to a CSV injection vulnerability when exporting data to a CSV file, as it fails to sanitize cell content beginning with special formula characters like =, +, -, or @. A local attacker can exploit this by running a process with a crafted name starting with =, which injects malicious formulas into the CSV output that execute when a victim opens the file in a spreadsheet application.Β The issue was addressed by pull request #117
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΠ΅ΠΉ Π½Π° ΡΡΡΠ°Π½ΠΈΡΡ
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΡ | CVSS | EPSS | ΠΠΏΡΠ±Π»ΠΈΠΊΠΎΠ²Π°Π½ΠΎ | |
|---|---|---|---|---|
CVE-2026-56652 Dool in versions up to 1.3.8 is vulnerable to a CSV injection vulnerability when exporting data to a CSV file, as it fails to sanitize cell content beginning with special formula characters like =, +, -, or @. A local attacker can exploit this by running a process with a crafted name starting with =, which injects malicious formulas into the CSV output that execute when a victim opens the file in a spreadsheet application.Β The issue was addressed by pull request #117 | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | 12 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄ | ||
CVE-2026-56652 Dool in versions up to 1.3.8 is vulnerable to a CSV injection vulnerab ... | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | 12 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄ | ||
GHSA-w3j2-f8wq-g63j Dool in versions up to 1.3.8 is vulnerable to a CSV injection vulnerability when exporting data to a CSV file, as it fails to sanitize cell content beginning with special formula characters like =, +, -, or @. A local attacker can exploit this by running a process with a crafted name starting with =, which injects malicious formulas into the CSV output that execute when a victim opens the file in a spreadsheet application.Β The issue was addressed by pull request #117 | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | 12 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄ |
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΠ΅ΠΉ Π½Π° ΡΡΡΠ°Π½ΠΈΡΡ