CVE-2026-53474

Source
https://cve.org/CVERecord?id=CVE-2026-53474
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53474.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-53474
Aliases
Published
2026-06-10T13:55:38.943Z
Modified
2026-08-18T15:10:44.877139634Z
Severity
  • 9.6 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N CVSS Calculator
Summary
Migration-planner: second-order sql injection via rvtools upload
Details

A flaw was found in migration-planner. A remote authenticated attacker could exploit this vulnerability by uploading a specially crafted RVTools .xlsx file. Due to improper input sanitization, malicious SQL embedded within a spreadsheet cell is executed when cluster names are processed. This SQL Injection allows for arbitrary file reading on the system, potentially exposing sensitive information such as Kubernetes service account tokens and other credentials, which could lead to a full compromise of the SaaS environment.

Database specific
{
    "cna_assigner": "redhat",
    "cwe_ids": [
        "CWE-89"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53474.json"
}
References

Affected packages

Git / github.com/kubev2v/migration-planner

Affected ranges

Type
GIT
Repo
https://github.com/kubev2v/migration-planner
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.13.5"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ],
    "cpe": "cpe:2.3:a:kebev2v:migration_assessment:*:*:*:*:*:*:*:*"
}

Affected versions

0.*
0.1.1
0.1.2
0.1.3
0.1.4
0.1.4-1
v0.*
v0.10.0
v0.11.0
v0.12.0
v0.13.0
v0.13.1
v0.13.2
v0.13.3
v0.13.4
v0.2.0
v0.2.0-1
v0.2.1
v0.3.0
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.7.0
v0.8.0
v0.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53474.json"