Improper Neutralization of Formula Elements in a CSV File in snipe-it - #VU145081
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to execute formulas in a victim\'s spreadsheet context.
The vulnerability exists due to improper neutralization of formula elements in a csv file in ReportsController::postAssetAcceptanceReport when exporting the asset acceptance report to CSV. A remote user can inject a spreadsheet formula into user-editable report fields to execute formulas in a victim\'s spreadsheet context.
User interaction is required to download and open the exported CSV in a formula-evaluating spreadsheet application.