CVE Vulnerabilities

CVE-2025-61873

Improper Neutralization of Formula Elements in a CSV File

Published: Jan 16, 2026 | Modified: Jan 26, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used.

Weakness

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Affected Software

NameVendorStart VersionEnd Version
Request-tracker4Ubuntuplucky*
Request-tracker5Ubuntuplucky*

Potential Mitigations

References