{"id":"GHSA-pw67-xjhq-389w","summary":"Pycel allows code injection via a crafted formula","details":"Pycel through 1.0b30, when operating on an untrusted spreadsheet, allows code execution via a crafted formula in a cell, such as one beginning with the `=IF(A1=200, eval(\"__import__('os').system(` substring.","aliases":["CVE-2024-53924","PYSEC-2025-177"],"modified":"2026-06-08T19:15:12.476003987Z","published":"2025-04-17T18:31:23Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-04-22T17:04:11Z","nvd_published_at":"2025-04-17T18:15:47Z","cwe_ids":["CWE-94"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-53924"},{"type":"WEB","url":"https://gist.github.com/aelmosalamy/cb098e61939718d2bb248fd1cc94f287"},{"type":"WEB","url":"https://github.com/dgorissen/pycel"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pycel/PYSEC-2025-177.yaml"},{"type":"PACKAGE","url":"https://github.com/stephenrauch/pycel"},{"type":"WEB","url":"https://pypi.org/project/pycel"}],"affected":[{"package":{"name":"pycel","ecosystem":"PyPI","purl":"pkg:pypi/pycel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.0b30"}]}],"versions":["1.0b0","1.0b11","1.0b12","1.0b13","1.0b14","1.0b15","1.0b16","1.0b17","1.0b18","1.0b19","1.0b2","1.0b20","1.0b21","1.0b22","1.0b26","1.0b27","1.0b28","1.0b29","1.0b3","1.0b30","1.0b4","1.0b5","1.0b6","1.0b7","1.0b8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-pw67-xjhq-389w/GHSA-pw67-xjhq-389w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"}]}