← Back

CVE-2024-53924

nvd nist
Published: Apr 17, 2025Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Pycel through 1.0b30, when operating on an untrusted spreadsheet, allows code execution via a crafted formula in a cell, such as one beginning with the =IF(A1=200, eval("__import__('os').system( substring.

Affected (25)

Products: Dgorissen: Pycel
1 product
Pycel
Configuration A
25 vulnerable
Vulnerable SoftwareAffected Versions
Dgorissen
Version 1.0 beta0
Version 1.0 beta11
Version 1.0 beta12
Version 1.0 beta13
Version 1.0 beta14
Version 1.0 beta15
Version 1.0 beta16
Version 1.0 beta17
Version 1.0 beta18
Version 1.0 beta19
Version 1.0 beta20
Version 1.0 beta21
Version 1.0 beta22
Version 1.0 beta26
Version 1.0 beta27
Version 1.0 beta28
Version 1.0 beta29
Version 1.0 beta2
Version 1.0 beta30
Version 1.0 beta3
Version 1.0 beta4
Version 1.0 beta5
Version 1.0 beta6
Version 1.0 beta7
Version 1.0 beta8

References (5)

Source: cve@mitre.org
ExploitThird Party Advisory
Source: cve@mitre.org
Product
Source: cve@mitre.org
Product
Source: cve@mitre.org
Product
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitThird Party Advisory

Timeline

No history available yet.