CSV Export Vulnerability in Brainstorm Force SureForms Product
CVE-2026-19501
Currently unrated
What is CVE-2026-19501?
The SureForms product by Brainstorm Force contains a vulnerability in its CSV export functionality, present in versions 2.1.1 and earlier. The flaw arises from the failure to sanitize user-controlled form field names, which can include spreadsheet formula characters. This oversight allows a remote attacker to create a malicious CSV file that, when opened in a vulnerable spreadsheet application, executes arbitrary formulas on the administrator's workstation, potentially leading to unauthorized actions or data exfiltration.
Affected Version(s)
SureForms 0 <= 2.1.1
