---
id: CVE-2025-31978
title: >-
  HCL BigFix Service Management (SM) does not adequately sanitize or safely
  render spreadsheet files (CSV, XLS, XLSX) before processing or distributing
  them
summary: >-
  HCL BigFix Service Management (SM) does not adequately sanitize or safely
  render spreadsheet files (CSV, XLS, XLSX) before processing or distributing
  them. An attacker could populate data fields which, when saved to a CSV file,
  may attem…
severity: medium
cvss: 4.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'
cwe:
  - CWE-201
vendor: hcltech
product: bigfix_service_management
affected:
  - bigfix_service_management = 23.0
published: '2026-05-06'
updated: '2026-06-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-31978'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0128144
    label: psirt@hcl.com
tags:
  - nvd
epss: 0.00137
epssPercentile: 0.02574
ingestedAt: '2026-06-29T15:48:27.659Z'
---

## Overview

HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or distributing them. An attacker could populate data fields which, when saved to a CSV file, may attempt information exfiltration or other malicious activity when automatically executed by the spreadsheet software. Note that current versions of Excel warn users of untrusted content.

## Affected

- `bigfix_service_management = 23.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
