A AegiFlow
CRITICALCVSS 9.6EPSS 0.3%

CVE-2026-53474

Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands

Published
2026-06-10
Modified
2026-08-14
EPSS percentile
22%
Aliases
GHSA-vf2h-7x3w-97fr
Sources
github-advisory

Summary

A flaw was found in migration-planner. A remote authenticated attacker could exploit this vulnerability by uploading a specially crafted RVTools .xlsx file. Due to improper input sanitization, malicious SQL embedded within a spreadsheet cell is executed when cluster names are processed. This SQL Injection allows for arbitrary file reading on the system, potentially exposing sensitive information such as Kubernetes service account tokens and other credentials, which could lead to a full compromise of the SaaS environment.

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogithub.com/kubev2v/migration-planner0.13.5

Remediation: Upgrade to 0.13.5 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.