CVE-2025-52386 Information

Description

CycloneDX Sunshine v0.9 is vulnerable to CSV Formula Injection via a crafted JSON file

Reference

https://github.com/CycloneDX/Sunshine https://github.com/VishalSreenivas/Formula-Injection-in-CycloneDX-Sunshine/blob/main/CVE-2025-52386.md https://github.com/VishalSreenivas/Formula-Injection-in-CycloneDX-Sunshine/blob/main/payload.json

CNNVD-202508-1373 (Published: 2025-08-13)

Share on: