CVE-2026-5242: Pizzy Library Code Injection via CSV Formula Injection (CVSS 8.8)
MIA Technology Inc.'s Pizzy Library contains a code injection vulnerability stemming from improper handling of formula elements in CSV files. An authenticated attacker can exploit this to execute arbitrary code within the application's context. The vulnerability affects versions 1.0.0.26250 through 1.3.8.26250, with version 1.3.9.26250 and later providing the fix.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 8.8 HIGH · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-1236
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-15 / 2026-06-17
NVD description (verbatim)
Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc. Pizzy Library allows Code Injection. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-5242 is a code injection vulnerability (CWE-1236) triggered by insufficient neutralization of formula syntax in CSV input processing. The Pizzy Library fails to sanitize or escape formula characters—typically leading characters like '=', '+', '@', or '-' that trigger formula evaluation in spreadsheet applications—before processing CSV data. An authenticated user with permission to upload or import CSV files can craft malicious input containing formula injection payloads, leading to arbitrary code execution within the application's privilege context.
Business impact
Successful exploitation enables authenticated users to execute arbitrary code with the permissions of the Pizzy Library process. This can lead to unauthorized data access, modification, or destruction; lateral movement within the network; and potential compromise of downstream systems that consume or interact with the library. Organizations relying on Pizzy for data import workflows face direct risk to data integrity and confidentiality. The HIGH severity rating reflects the combination of high impact (confidentiality, integrity, availability all affected) and ease of exploitation once authentication is obtained.
Affected systems
MIA Technology Inc. Pizzy Library versions 1.0.0.26250 through 1.3.8.26250 are vulnerable. Any application or workflow integrating the Pizzy Library for CSV processing is affected if users can directly supply or influence CSV content. This includes data import pipelines, batch processing systems, and integration middleware that rely on this library.
Exploitability
Exploitation requires valid authentication credentials (PR:L in the CVSS vector) but does not require user interaction. An authenticated attacker with CSV upload or import privileges can trigger code injection without social engineering or additional clicks. Network accessibility (AV:N) means attacks can be mounted remotely. The low complexity (AC:L) indicates no special conditions are needed—any authenticated session is sufficient. Organizations with permissive access controls for data import functions face higher risk.
Remediation
Upgrade Pizzy Library to version 1.3.9.26250 or later. Verify the upgrade through vendor release notes and test in a non-production environment before deploying to production systems. No workarounds short of disabling CSV import functionality are known; patching is the primary mitigation path.
Patch guidance
Update all instances of Pizzy Library to version 1.3.9.26250 or a later supported release. Coordinate this with your application dependency management and testing cycle. Verify compatibility with your application version before deployment. Check MIA Technology Inc.'s official advisory for any additional upgrade prerequisites or breaking changes. If you cannot patch immediately, implement network segmentation to restrict access to CSV import features to trusted users only.
Detection guidance
Monitor for CSV file uploads or imports that contain unusual characters or formula syntax (e.g., '=', '+', '@', '-' at the start of cell values). Log and alert on authentication events preceding CSV import operations, especially from unusual locations or at off-hours. Inspect running processes spawned by Pizzy Library for unexpected child processes or privileged operations. Maintain audit logs of all data import activities and correlate with system behavior changes. Security scanning tools that detect formula injection payloads in file uploads may also be beneficial.
Why prioritize this
This vulnerability merits urgent attention due to its HIGH CVSS score (8.8), broad impact across confidentiality, integrity, and availability, and the ease with which authenticated users can exploit it. While authentication is required, many organizations permit multiple users to import data. The code execution capability and network accessibility make this a critical pathway for post-compromise lateral movement and data exfiltration. Prioritize patching in environments where CSV import is commonly used or where users have broad data import permissions.
Risk score, explained
The CVSS 3.1 score of 8.8 (HIGH) is driven by: (1) Network accessibility allowing remote exploitation, (2) low attack complexity requiring no special conditions, (3) authentication requirement reducing but not eliminating risk for typical environments, (4) full impact on confidentiality, integrity, and availability of the affected system, and (5) no scope boundary—the vulnerability is confined to the system running the library. This is a severe vulnerability that can enable complete system compromise.
Frequently asked questions
Do we need to update immediately if we don't allow unauthenticated CSV imports?
Yes. While authentication is required, you should assess whether your current user population has overly permissive import privileges. Even if you believe access is restricted, the vulnerability enables authenticated code execution, which can facilitate lateral movement and privilege escalation. Prioritize patching within your normal maintenance window, but treat it as high-priority.
What should we do if we can't patch Pizzy Library immediately?
Implement compensating controls: restrict CSV import functionality to a small group of trusted administrators, enforce multi-factor authentication for accounts that use CSV import, disable CSV import features in non-critical environments temporarily, monitor all import activities closely, and isolate systems running the library from sensitive network resources. These do not replace patching but reduce exploitability window.
How do we know if our applications use the vulnerable Pizzy Library?
Review your application's dependency manifests (package files, compiled binary manifests, or library inventories). Search for 'Pizzy' or 'MIA Technology' in your Software Bill of Materials (SBOM). If you use data integration, ETL, or data import tools from third parties, contact those vendors to determine if they depend on Pizzy Library and whether they have released updates addressing this issue.
Is formula injection really a code execution vulnerability?
Yes. Formula injection in CSV files, when imported into spreadsheet applications or libraries that evaluate formulas, can trigger execution of embedded commands or scripts. Modern libraries like Pizzy may evaluate formulas to provide feature parity with spreadsheet applications, creating this attack surface. The risk is real even in non-spreadsheet contexts.
This analysis is based on publicly disclosed information as of June 2026. No active exploitation in the wild has been confirmed at publication time; however, KEV status was not available. Organizations should verify patch availability and compatibility with their specific Pizzy Library deployment and dependent applications before applying updates. This assessment does not constitute professional security advice; consult your internal security team or a qualified security consultant for guidance tailored to your environment. Source: NVD (public-domain), retrieved 2026-07-24. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2025-52612HIGHHCL iControl CSV Injection & Reflected XSS Vulnerability – CVSS 7.1
- CVE-2026-10248MEDIUMCSV Injection in SourceCodester Pharmacy Sales and Inventory System
- CVE-2026-9673MEDIUMCSV Injection in json-2-csv Library (Versions ≤5.5.10)
- CVE-2016-20062HIGHSQL Injection in Simply Poll 1.4.1 WordPress Plugin - Unauthenticated Data Theft
- CVE-2016-20063HIGHSQL Injection in Single Personal Message 1.0.3 – Credential & Data Theft Risk
- CVE-2016-20065HIGHUnauthenticated SQL Injection in Product Catalog 8 WordPress Plugin
- CVE-2016-20066HIGHWordPress CP Polls 1.0.8 Persistent XSS Vulnerability
- CVE-2016-20068HIGHUnauthenticated SQL Injection in WordPress Booking Calendar Contact Form 1.0.23