CSV Formula Injection in CycloneDX Sunshine by CycloneDX
CVE-2025-52386
5.4MEDIUM
What is CVE-2025-52386?
CycloneDX Sunshine version 0.9 is susceptible to a vulnerability that allows CSV formula injection through a specially crafted JSON file. This issue can be exploited by an attacker who crafts a malicious JSON file that, when processed by the application, could lead to arbitrary code execution within spreadsheet applications, potentially compromising sensitive data integrity. Users of CycloneDX Sunshine should ensure their systems are updated to mitigate this vulnerability immediately.