Junglewise Threat Intelligence

CVE-2026-45263: FacturaScripts CSV formula injection in CSVExport

CVE-2026-45263 · Severity: high · CVSS 8 · Published 2026-07-14

Technologies: NeoRazorX FacturaScripts, facturascripts/facturascripts (Packagist). Vendors: NeoRazorX, Packagist.

Executive brief

FacturaScripts is an open-source ERP and accounting system. A vulnerability in its CSV export feature allows low-privileged users (such as sales or accounting staff) to inject malicious formulas into data fields like customer names or product descriptions. When an administrator later exports this data to a CSV file and opens it in a spreadsheet application like Excel or LibreOffice, the malicious code can execute on the administrator's computer, potentially leading to full system takeover or data theft.

Technical details

A CSV formula injection vulnerability exists in FacturaScripts due to insufficient sanitization of leading characters in the CSVExport class. The `CSVExport::writeData()` method in `Core/Lib/Export/CSVExport.php` fails to neutralize characters that trigger formula execution in spreadsheet software (e.g., `=`, `+`, `-`, `@`). While the application sanitizes HTML characters, it does not address spreadsheet meta-characters. An authenticated low-privileged attacker can input a malicious payload (such as a DDE command) into a model field (e.g., Cliente, Producto). When an administrator triggers a CSV export via the `?action=export&option=CSV` controller, the payload is included verbatim. Opening the resulting file in Excel or LibreOffice can lead to arbitrary command execution or data exfiltration from the administrator's workstation.

Affected products

  • NeoRazorX FacturaScripts <= 2026.1

Timeline

  • 2026-04-30: other: PoC verified against master branch
  • 2026-07-14: advisory: GitHub Advisory published

References

Related threats