CVE-2024-53924
Pycel through 1.0b30, when operating on an untrusted spreadsheet, allows code execution via a crafted formula in a cell, such as one beginning with the =IF(A1=200, eval("import('os').system( substring.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/dgorissen/pycel, https://github.com/stephenrauch/pycel, https://pypi.org/project/pycel/, https://gist.github.com/aelmosalamy/cb098e61939718d2bb248fd1cc94f287, https://github.com/advisories/GHSA-pw67-xjhq-389w