CVE-2026-42267

medium
Published 2026-05-05 · Modified 2026-05-14
CVSS v3
5.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
CVSS v2
VIR risk
5.7

Description

Kimai vulnerable to formula Injection via tag names in XLSX export

Predictions

Exploit likelihood
67%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/kimai/kimai/security/advisories/GHSA-3xc2-h5r3-wv3r

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/kimai/kimai/releases/tag/2.54.0

Package impact

EcosystemPackageVulnerableFixed
php Packagistkimai/kimai>=2.27.0,<=2.53.0
php Packagistkimai/kimai>=2.27.0,<2.54.02.54.0
php COMPOSERkimai/kimai>= 2.27.0, <= 2.53.02.54.0

Application impact

VendorProductVersionsFixed
kimaikimai{"startIncluding":"2.27.0","endExcluding":"2.54.0"}2.54.0

References

CWEs

CWE-1236

Verify integrity in audit chain (admin only). AS-IS.