Junglewise Threat Intelligence

CVE-2025-66834: TrueConf Server CSV formula injection via Display Name

CVE-2025-66834 · Severity: high · CVSS 7.3 · Published 2025-12-30

Technologies: TrueConf Server. Vendors: Trueconf.

Executive brief

TrueConf Server is a self-hosted video conferencing and corporate messaging platform. A formula injection vulnerability in its chat reporting feature allows an attacker to embed malicious spreadsheet formulas in exported CSV files by manipulating their display name. When an administrator opens the exported chat logs in a spreadsheet application, the formula executes automatically, potentially leading to code execution or data theft.

Technical details

TrueConf Server v5.5.2.10813 contains a CSV formula injection vulnerability (CWE-1236) in the chat message export functionality. User-controlled Display Name fields are written directly into exported CSV files without sanitization or escaping of formula-triggering characters (=, +, -, @, |). An authenticated attacker can inject malicious spreadsheet formulas via their profile; when an administrator exports chat messages through the Admin Panel and opens the resulting CSV file in a spreadsheet application that evaluates formulas, the payload executes with the privileges of the user opening the file. The attack requires the attacker to be a valid user and the administrator to both export and open the CSV file. Potential impacts include arbitrary command execution and information disclosure. No patch is currently documented in the advisory.

Affected products

  • TrueConf Server v5.5.2.10813

Timeline

  • 2025-12-30: disclosed: CVE-2025-66834 published
  • 2025-11-23: other: Vulnerability discovered by Morteza Maleki

References

Related threats