CVE-2026-5242 Details
Description
Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc. Pizzy Library allows Code Injection. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.
A code injection vulnerability has been identified in the Pizzy Library developed by MIA Technology Inc. This issue arises from improper neutralization of formula elements in CSV files, allowing for malicious code to be executed. The vulnerability affects Pizzy Library versions from 1.0.0.26250 prior to 1.3.9.26250.
Users are advised to upgrade to Pizzy Library version 1.3.9.26250 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 15, 2026CISA-ADP
Assessed Jun 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0383 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1236 | Improper Neutralization of Formula Elements in a CSV File | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| MIA Technology Inc. Pizzy Library | >= 1.0.0.26250, < 1.3.9.26250 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 15, 2026 | New CVE Received | [email protected] |
Volerion