CVE-2026-65875
Received Received - Intake

CSV Injection Vulnerability in BaserCMS

Vulnerability report for CVE-2026-65875, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: JPCERT/CC

Description

BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malicious code injected by an attacker, the malicious code may be executed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
basercms_users_community basercms *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1236 The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

BaserCMS contains a CSV file injection vulnerability. If a user downloads and opens a CSV file with malicious code injected by an attacker, the malicious code may execute on the user's system.

Detection Guidance

Detecting CSV file injection vulnerabilities typically involves monitoring for unusual CSV files or suspicious content within them. Check for files with unexpected scripts or commands embedded in cells. Inspect downloaded CSV files for macros or executable code before opening.

Impact Analysis

This vulnerability could allow an attacker to execute arbitrary code on your system when you open a maliciously crafted CSV file downloaded from a vulnerable BaserCMS instance.

Compliance Impact

This vulnerability could potentially affect compliance with GDPR and HIPAA by enabling unauthorized code execution through malicious CSV files. If exploited, it may lead to data breaches or unauthorized access, violating confidentiality and integrity requirements under these regulations.

Mitigation Strategies

To mitigate this vulnerability, avoid downloading or opening CSV files from untrusted sources. Ensure your CSV software or applications are updated to handle CSV files safely. Implement input validation to block malicious payloads in CSV files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-65875. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart