Code Injection Vulnerability in Bagisto eCommerce Platform from Laravel
CVE-2025-62417
What is CVE-2025-62417?
The Bagisto eCommerce platform, built on Laravel, is susceptible to a code injection vulnerability that arises when product data containing formula characters (=, +, -, @) is accepted. When such data is saved and exported as a CSV, and subsequently opened in spreadsheet applications, the formulas can be evaluated. This opens a potential attack vector allowing malicious users to exploit the functionality, risking data exfiltration and possibly leading to remote command execution via vulnerabilities in older versions of Excel. Users are urged to update to version 2.3.8 to mitigate these risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
bagisto < 2.3.8
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
