Improper Neutralization of Formula Elements in a CSV File in snipe-it - CVE-2026-55452
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote user to execute attacker-controlled formulas in spreadsheet software.
The vulnerability exists due to improper neutralization of formula elements in CSV export in ReportsController::postActivityReport() when exporting activity report data containing a user-supplied User-Agent value. A remote user can supply a formula-like User-Agent header and perform a logged action to execute attacker-controlled formulas in spreadsheet software.
User interaction is required to export the Activity Report and open it in spreadsheet software.