Code Injection Vulnerability in Bagisto eCommerce Platform from Laravel
CVE-2025-62417

7.1HIGH

Key Information:

Vendor

Bagisto

Status
Vendor
CVE Published:
16 October 2025

What is CVE-2025-62417?

The Bagisto eCommerce platform, built on Laravel, is susceptible to a code injection vulnerability that arises when product data containing formula characters (=, +, -, @) is accepted. When such data is saved and exported as a CSV, and subsequently opened in spreadsheet applications, the formulas can be evaluated. This opens a potential attack vector allowing malicious users to exploit the functionality, risking data exfiltration and possibly leading to remote command execution via vulnerabilities in older versions of Excel. Users are urged to update to version 2.3.8 to mitigate these risks.

Affected Version(s)

bagisto < 2.3.8

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-62417 : Code Injection Vulnerability in Bagisto eCommerce Platform from Laravel