Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1110 CNY

100%

CVE-2026-41073— RT: Spreadsheet downloads vulnerable to CSV/formula injection in Microsoft Excel and similar apps

CVSS 4.6 · Medium
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-41073

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
RT: Spreadsheet downloads vulnerable to CSV/formula injection in Microsoft Excel and similar apps
Source: NVD (National Vulnerability Database)
Vulnerability Description
RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10 and 6.0.0 through 6.0.2 contain a spreadsheet (CSV/formula) injection vulnerability. User-controlled data in spreadsheet exports is not sanitized before being written to the output file, which can cause spreadsheet applications to interpret crafted values as formulas or macros when the file is opened. This issue has been fixed in versions 5.0.10 and 6.0.3. If developers are unable to upgrade immediately, they can temporarily work around this issue by avoiding opening exported RT spreadsheet files directly in spreadsheet applications when the data may contain untrusted user input.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
CWE-1236
Source: NVD (National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
bestpracticalrt < 5.0.10 -

II. Public POCs for CVE-2026-41073

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-41073

登录查看更多情报信息。

Vendor Advisories for CVE-2026-41073 (1)

Vendor Pages for CVE-2026-41073 (2)

Same Patch Batch · bestpractical · 2026-05-22 · 4 CVEs total

CVE-2026-410758.8 HIGHRT: SQL injection via entry_aggregator parameter in JSON search
CVE-2026-410768.1 HIGHRT: LDAP authentication bypass via empty password
CVE-2026-410747.1 HIGHRT has broken CSRF protection for authenticated users

IV. Related Vulnerabilities

V. Comments for CVE-2026-41073

No comments yet


Leave a comment