Improper Neutralization of Formula Elements in a CSV File in snipe-it - #VU145084
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to execute formulas in a victim\'s spreadsheet context.
The vulnerability exists due to improper neutralization of formula elements in a csv file in SettingsController::downloadLocationScopingReport when exporting location-scoping report data to CSV. A remote user can place a spreadsheet formula in user-editable report fields to execute formulas in a victim\'s spreadsheet context.
User interaction is required when a superuser downloads the export and opens it in a formula-evaluating spreadsheet application.