CVE-2026-56652: Formula Injection in dool project

Published Aug 27, 2026
·
Updated

Dool in versions up to 1.3.8 is vulnerable to a CSV injection vulnerability when exporting data to a CSV file, as it fails to sanitize cell content beginning with special formula characters like =, +, -, or @. A local attacker can exploit this by running a process with a crafted name starting with =, which injects malicious formulas into the CSV output that execute when a victim opens the file in a spreadsheet application.  The issue was addressed by pull request #117

Affected Software

1 affected component
dool<=1.3.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade dool to a version that resolves this vulnerability.

    Fixed in 1.3.8Patch pull request #117

Event History

Aug 27, 2026
CVE Published
via MITRE·01:22 PM
Data Sourced
via MITRE·01:22 PM
DescriptionWeakness
Data Sourced
via NVD·05:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Users who export Dool data to CSV and then open the resulting file in a spreadsheet application are exposed. Exploitation requires that the exported data include a process name crafted to begin with =, +, -, or @.

2

What access does an attacker need?

The attacker needs local access sufficient to run a process with a crafted name on the system where Dool collects data. The malicious formula executes only when a victim opens the generated CSV in a spreadsheet application.

3

How can I tell whether CSV output may be affected?

Inspect exported CSV files for cell values, particularly process names, beginning with =, +, -, or @. Such values may be interpreted as spreadsheet formulas when the file is opened.

4

What can be done if updating is not immediately possible?

Avoid opening Dool CSV exports in spreadsheet applications when process names may be attacker-controlled. Review or sanitize cells beginning with =, +, -, or @ before opening the file.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203