If a malformed data is input to the affected product, a CSV file downloaded from the affected product may contain such malformed data. When a victim user download and open such a CSV file, the embedded code may be executed in the user's environment. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well.
Metrics
Affected Vendors & Products
References
History
Wed, 04 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 04 Feb 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | If a malformed data is input to the affected product, a CSV file downloaded from the affected product may contain such malformed data. When a victim user download and open such a CSV file, the embedded code may be executed in the user's environment. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well. | |
| Weaknesses | CWE-1236 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published: 2026-02-04T07:04:04.422Z
Updated: 2026-02-04T15:55:26.690Z
Reserved: 2026-01-29T02:02:27.800Z
Link: CVE-2026-24447
Updated: 2026-02-04T15:55:22.739Z
Status : Awaiting Analysis
Published: 2026-02-04T07:16:01.560
Modified: 2026-02-04T16:33:44.537
Link: CVE-2026-24447
No data.