CVE-2024-53924: Pycel through 1.0b30, when operating on an untrusted spreadsheet, allows code execution via a crafted formula in a cell, such as one beginning with...

Description

Pycel through 1.0b30, when operating on an untrusted spreadsheet, allows code execution via a crafted formula in a cell, such as one beginning with the =IF(A1=200, eval("__import__('os').system( substring.

Classification

CVE ID: CVE-2024-53924

Affected Products

Vendor: n/a

Product: n/a

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.02% (probability of being exploited)

EPSS Percentile: 3.05% (scored less or equal to compared to others)

EPSS Date: 2025-04-18 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2024-53924
https://pypi.org/project/pycel/
https://github.com/stephenrauch/pycel
https://github.com/dgorissen/pycel
https://gist.github.com/aelmosalamy/cb098e61939718d2bb248fd1cc94f287

Timeline