CSV Export Vulnerability in Traccar GPS Tracking System
CVE-2026-27644
6.5MEDIUM
What is CVE-2026-27644?
The Traccar GPS tracking system's CSV export feature, in versions 6.11.1 to 6.13.0, is susceptible to manipulation due to improper escaping of user-input data in output files. This flaw allows an attacker to embed malicious spreadsheet formulas within the exported CSV, which may execute commands or exfiltrate sensitive data upon opening the file in spreadsheet software. The vulnerability has been addressed in version 6.13.0, emphasizing the necessity for users to update and secure their installations.
Affected Version(s)
traccar >= 6.11.1 , < 6.13.0
traccar >= 6.11.1 , < 6.13.0
