CVE-2026-12862 PUBLISHED

XLSX formula injection in exports

Assigner: rami.io
Reserved: 22.06.2026 Published: 22.06.2026 Updated: 22.06.2026

Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be used to compromise the environment of the user loading the file or other data in the file.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
CVSS Score: 5.1

Product Status

Vendor pretix
Product Venueless
Versions Default: unaffected
  • affected from 0.0.0 to 0a35457f (excl.)

Credits

  • Rokkam Vamshi finder

References

Problem Types

  • CWE-148 Improper neutralization of input leaders CWE

Impacts

  • CAPEC-23 File Content Injection