A CSV formula injection vulnerability (GHSA-xf4v-w5x5-pv79, CWE-1236) has been disclosed in the Spree e-commerce gem. User-controlled fields such as customer names, email addresses, and shipping addresses are not sanitized before being written to CSV exports. When an administrator opens the exported file in Microsoft Excel or LibreOffice Calc, embedded formulas can execute in the administrator's desktop context, potentially enabling data exfiltration or OS command execution via DDE. Patched versions are 5.2.8, 5.3.6, and 5.4.3. Versions below 5.2.0 are unaffected.

1m read timeFrom rubysec.com
Post cover image
Table of contents
ImpactWho is impacted
322 Impressions