{"api_version":"1","generated_at":"2026-08-20T15:51:42+00:00","cve":"CVE-2026-19501","urls":{"html":"https://cve.report/CVE-2026-19501","api":"https://cve.report/api/cve/CVE-2026-19501.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-19501","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-19501"},"summary":{"title":"CVE-2026-19501","description":"CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute spreadsheet formulas on an administrator's workstation when the exported CSV file is opened in a vulnerable spreadsheet application.","state":"PUBLISHED","assigner":"certcc","published_at":"2026-08-18 16:17:02","updated_at":"2026-08-19 14:17:30"},"problem_types":["CWE-1236 Improper Neutralization of Formula Elements in a CSV File"],"metrics":[],"references":[{"url":"https://github.com/typedefabcd1234ntd/CVE-2026-19501-poc","name":"https://github.com/typedefabcd1234ntd/CVE-2026-19501-poc","refsource":"cret@cert.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://sureforms.com","name":"http://sureforms.com","refsource":"cret@cert.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-19501","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19501","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"SureForms","product":"SureForms","version":"affected 2.12.1 custom","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"19501","cve":"CVE-2026-19501","epss":"0.003390000","percentile":"0.269890000","score_date":"2026-08-19","updated_at":"2026-08-20 00:13:10"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"product":"SureForms","vendor":"SureForms","versions":[{"lessThanOrEqual":"2.12.1","status":"affected","version":"0","versionType":"custom"}]}],"descriptions":[{"lang":"en","value":"CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute spreadsheet formulas on an administrator's workstation when the exported CSV file is opened in a vulnerable spreadsheet application."}],"problemTypes":[{"descriptions":[{"description":"CWE-1236 Improper Neutralization of Formula Elements in a CSV File","lang":"en"}]}],"providerMetadata":{"dateUpdated":"2026-08-19T13:40:41.174Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"url":"http://sureforms.com"},{"url":"https://github.com/typedefabcd1234ntd/CVE-2026-19501-poc"}],"source":{"discovery":"UNKNOWN"},"title":"CVE-2026-19501","x_generator":{"engine":"VINCE 3.0.44","env":"prod","origin":"https://cveawg.mitre.org/api/cve/CVE-2026-19501"}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2026-19501","datePublished":"2026-08-18T15:21:36.115Z","dateReserved":"2026-08-10T18:58:04.964Z","dateUpdated":"2026-08-19T13:40:41.174Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-18 16:17:02","lastModifiedDate":"2026-08-19 14:17:30","problem_types":["CWE-1236 Improper Neutralization of Formula Elements in a CSV File"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"19501","Ordinal":"1","Title":"CVE-2026-19501","CVE":"CVE-2026-19501","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"19501","Ordinal":"1","NoteData":"CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute spreadsheet formulas on an administrator's workstation when the exported CSV file is opened in a vulnerable spreadsheet application.","Type":"Description","Title":"CVE-2026-19501"}]}}}