VYPR

Dool

by Scottchiefbaker

CVEs (2)

  • CVE-2026-56652MedAug 27, 2026
    risk 0.23cvss epss

    Dool in versions up to 1.3.8 is vulnerable to a CSV injection vulnerability when exporting data to a CSV file, as it fails to sanitize cell content beginning with special formula characters like =, +, -, or @. A local attacker can exploit this by running a process with a crafted…

  • CVE-2026-56651LowAug 27, 2026
    risk 0.06cvss epss

    Dool in versions up to 1.3.8 is vulnerable to symlink following when the "--devel" flag is used, as the application opens a log file without the "O_NOFOLLOW" flag. A local attacker can exploit this by creating a symlink at the expected log file path pointing to a sensitive…