<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T13:54:46.651284+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-309121</id>
    <title>EUVD-2026-309121</title>
    <updated>2026-10-08T13:54:46.704662+00:00</updated>
    <content>EUVD-2026-309121</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-309121"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42267</id>
    <title>fkie_cve-2026-42267</title>
    <updated>2026-10-08T13:54:46.704708+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Kimai is an open-source time tracking application. From version 2.27.0 to before version 2.54.0, any ROLE_USER can create a tag with a formula string as its name (e.g. =SUM(54+51)) via POST /api/tags and assign it to a timesheet. When an admin exports timesheets to XLSX, ArrayFormatter.formatValue() joins tag names with implode() and returns the result unchanged. OpenSpout promotes any =-prefixed string to a FormulaCell, writing &lt;f&gt;SUM(54+51)&lt;/f&gt; into the XLSX archive. Excel evaluates the formula when the file is opened. This issue has been patched in version 2.54.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42267"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3xc2-h5r3-wv3r</id>
    <title>GHSA-3xc2-h5r3-wv3r — Kimai vulnerable to formula Injection via tag names in XLSX export</title>
    <updated>2026-10-08T13:54:46.704763+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: kimai/kimai</p>
<p>## Summary</p>
<p>Any `ROLE_USER` can create a tag with a formula string as its name (e.g. `=SUM(54+51)`) via `POST /api/tags` and assign it to a timesheet. When an admin exports timesheets to XLSX, `ArrayFormatter.formatValue()` joins tag names with `implode()` and returns the result unchanged. OpenSpout promotes any `=`-prefixed string to a `FormulaCell`, writing `&lt;f&gt;SUM(54+51)&lt;/f&gt;` into the XLSX archive. Excel evaluates the formula when the file is opened.</p>
<p>## Details</p>
<p>### 1. `ArrayFormatter` does not sanitize before returning</p>
<p>`sanitizeDDE()` exists on `StringHelper` and is called by `TextFormatter`, but `ArrayFormatter` never calls it.
```php
// src/Export/Package/CellFormatter/ArrayFormatter.php:24
return implode(', ', $value);  // no sanitizeDDE() call
```</p>
<p>### 2. Tag name validation does not block formula trigger characters</p>
<p>The API blocks commas in tag names but permits `=`, `+`, `-`, and `@` - all valid formula prefixes in Excel and LibreOffice Calc.</p>
<p>### 3. OpenSpout silently promotes strings to formula cells</p>
<p>`Cell::fromValue("=SUM(54+51)")` returns a `FormulaCell` with no warning.</p>
<p>### PoC</p>
<p>1. It logs in as normal user, creates tag `=SUM(54+51)`, assigns it to a timesheet.
2. Admin has to export timesheets to Excel version via `/en/export/` endpoint.</p>
<p>&lt;img width="1339" height="700" alt="image" src="https://github.com/user-attachments/assets/884c7943-5e3b-4647-8bcc-e264d6719d66" /&gt;</p>
<p>&lt;img width="1304" height="128" alt="formula_injection_tags" src="https://github.com/use…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3xc2-h5r3-wv3r"/>
  </entry>
</feed>
