CVE Explorer
CVE-2026-27644
Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality writes position data, including user-controlled device and computed attributes, to CSV output without proper escaping. An attacker can inject spreadsheet formulas through exported fields. When a manager or administrator opens the exported CSV file in spreadsheet software, this can cause formula execution and lead to command execution or data exfiltration. This has been patched in ve
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
2 source assertions{"product":"traccar","vendor":"traccar","versions":[{"status":"affected","version":">= 6.11.1 , < 6.13.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8d657c872b67774cceb1983cac3a410d63c419d05836524e631200f09851ea82 · sha256:84bee41180a9b62a… · /containers/cna/affected/1
{"product":"traccar","vendor":"traccar","versions":[{"status":"affected","version":">= 6.11.1 , < 6.13.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8d657c872b67774cceb1983cac3a410d63c419d05836524e631200f09851ea82 · sha256:84bee41180a9b62a… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:8d657c872b67774cceb1983cac3a410d63c419d05836524e631200f09851ea82 · sha256:84bee41180a9b62a… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-1236","description":"CWE-1236: Improper Neutralization of Formula Elements in a CSV File","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8d657c872b67774cceb1983cac3a410d63c419d05836524e631200f09851ea82 · sha256:84bee41180a9b62a… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/traccar/traccar/blob/v6.11.1/src/main/java/org/traccar/reports/CsvExportProvider.java#L89-L91","tags":["x_refsource_MISC"],"url":"https://github.com/traccar/traccar/blob/v6.11.1/src/main/java/org/traccar/reports/CsvExportProvider.java#L89-L91"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8d657c872b67774cceb1983cac3a410d63c419d05836524e631200f09851ea82 · sha256:84bee41180a9b62a… · /containers/cna/references/1
{"tags":["exploit"],"url":"https://github.com/traccar/traccar/security/advisories/GHSA-745r-9qgj-x7m7"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8d657c872b67774cceb1983cac3a410d63c419d05836524e631200f09851ea82 · sha256:84bee41180a9b62a… · /containers/adp/0/references/0
{"name":"https://github.com/traccar/traccar/security/advisories/GHSA-745r-9qgj-x7m7","tags":["x_refsource_CONFIRM"],"url":"https://github.com/traccar/traccar/security/advisories/GHSA-745r-9qgj-x7m7"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8d657c872b67774cceb1983cac3a410d63c419d05836524e631200f09851ea82 · sha256:84bee41180a9b62a… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.