{"id":"CVE-2026-86257","title":"wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas","summary":"wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas. Attackers can inject formulas like =HYPERLINK to exfiltrate admin data or ex…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-1236"],"vendor":"wger-project","product":"wger","affected":["wger < 2.6"],"published":"2026-09-06","updated":"2026-09-08","sourceUpdated":"2026-09-08T19:59:42.500","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86257","references":[{"url":"https://github.com/wger-project/wger/security/advisories/GHSA-xq9m-hmp9-fw87","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/wger-before-2.6-csv-formula-injection-via-member-export","label":"disclosure@vulncheck.com"},{"url":"https://github.com/wger-project/wger/security/advisories/GHSA-xq9m-hmp9-fw87","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/wger-project/wger"}],"tags":["nvd","cve.org","exploit-available","osv","pip","score-dispute"],"epss":0.00167,"epssPercentile":0.0633,"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-08T15:09:37.303676Z"},"ingestedAt":"2026-09-07T04:04:50.805Z","aliases":["GHSA-xq9m-hmp9-fw87"],"ecosystem":"pip","patched":["wger 2.6"],"scores":{"nvd":5.4,"osv":7.4},"slug":"CVE-2026-86257","body":"## Overview\n\nwger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas. Attackers can inject formulas like =HYPERLINK to exfiltrate admin data or execute code when admins open the exported file in Excel or LibreOffice Calc.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-86257)\n\nAffected packages:\n\n- `wger < 2.6`\n\nPatched in:\n\n- `wger 2.6`\n\nSource: https://osv.dev/vulnerability/GHSA-xq9m-hmp9-fw87","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":5537,"id":"CVE-2026-86257","ts":1788887297480,"field":"exploit_available","old":"false","new":"true"},{"seq":4412,"id":"CVE-2026-86257","ts":1788886404757,"field":"exploit_available","old":"true","new":"false"},{"seq":3125,"id":"CVE-2026-86257","ts":1788883068633,"field":"exploit_available","old":"false","new":"true"},{"seq":2154,"id":"CVE-2026-86257","ts":1788882472626,"field":"exploit_available","old":"true","new":"false"},{"seq":311,"id":"CVE-2026-86257","ts":1788881649246,"field":"exploit_available","old":"false","new":"true"}]}