CVE-2024-53924
17.04.2025, 18:15
Pycel through 1.0b30, when operating on an untrusted spreadsheet, allows code execution via a crafted formula in a cell, such as one beginning with the =IF(A1=200, eval("__import__('os').system( substring.
Vendor | Product | Version |
---|---|---|
dgorissen | pycel | 1.0:beta0 |
dgorissen | pycel | 1.0:beta11 |
dgorissen | pycel | 1.0:beta12 |
dgorissen | pycel | 1.0:beta13 |
dgorissen | pycel | 1.0:beta14 |
dgorissen | pycel | 1.0:beta15 |
dgorissen | pycel | 1.0:beta16 |
dgorissen | pycel | 1.0:beta17 |
dgorissen | pycel | 1.0:beta18 |
dgorissen | pycel | 1.0:beta19 |
dgorissen | pycel | 1.0:beta2 |
dgorissen | pycel | 1.0:beta20 |
dgorissen | pycel | 1.0:beta21 |
dgorissen | pycel | 1.0:beta22 |
dgorissen | pycel | 1.0:beta26 |
dgorissen | pycel | 1.0:beta27 |
dgorissen | pycel | 1.0:beta28 |
dgorissen | pycel | 1.0:beta29 |
dgorissen | pycel | 1.0:beta3 |
dgorissen | pycel | 1.0:beta30 |
dgorissen | pycel | 1.0:beta4 |
dgorissen | pycel | 1.0:beta5 |
dgorissen | pycel | 1.0:beta6 |
dgorissen | pycel | 1.0:beta7 |
dgorissen | pycel | 1.0:beta8 |
𝑥
= Vulnerable software versions