{"id":"CVE-2026-19501","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-19501","summary":"CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV…","details":"CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute spreadsheet formulas on an administrator's workstation when the exported CSV file is opened in a vulnerable spreadsheet application.","published":"2026-08-18T16:17:02.780","modified":"2026-08-19T14:17:30.300","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"http://sureforms.com"},{"type":"WEB","url":"https://github.com/typedefabcd1234ntd/CVE-2026-19501-poc"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-19T14:17:30.300"}}