CVE-2025-50572

A

rcher 6.11.00204.10014 allows attackers to execute arbitrary code via crafted system inputs that would be exported into the CSV and be executed after the user opened the file with compatible applications. NOTE: the Supplier does not accept this as a valid vulnerability report against their product.

Configurations

No configuration.

History

12 Jan 2026, 09:15

Type Values Removed Values Added
Summary (en) An issue was discovered in Archer Technology RSA Archer 6.11.00204.10014 allowing attackers to execute arbitrary code via crafted system inputs that would be exported into the CSV and be executed after the user opened the file with compatible applications. (en) Archer 6.11.00204.10014 allows attackers to execute arbitrary code via crafted system inputs that would be exported into the CSV and be executed after the user opened the file with compatible applications. NOTE: the Supplier does not accept this as a valid vulnerability report against their product.
References
  • () https://www.archerirm.community/s/blogs/formula-injection-into-csv-files-vulnerability-in-rsa-archer-6-1-x-and-higher-MCOCQFO3WCQBCCHMKNC74JGSFWQY -

04 Aug 2025, 15:06

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-31 20:15

Updated : 2026-01-12 09:15


NVD link : CVE-2025-50572

Mitre link : CVE-2025-50572

CVE.ORG link : CVE-2025-50572


JSON object : View

Products Affected

No product.

CWE
CWE-1236

Improper Neutralization of Formula Elements in a CSV File