BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malicious code injected by an attacker, the malicious code may be executed.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
BaserCMS contains a CSV file injection vulnerability that allows attackers to embed malicious code within CSV files. When users download and open these files in spreadsheet applications like Excel or Google Sheets, the injected formulas execute automatically, potentially leading to arbitrary code execution on the user's system. This vulnerability affects BaserCMS users and administrators who regularly export or download data in CSV format. The attack is particularly insidious because it exploits the trusted nature of CSV downloads and the default behavior of spreadsheet applications to process formulas, making it difficult for non-technical users to recognize the threat.
Casky's Claude AI-powered analysis maps this attack to MITRE ATT&CK technique T1059.003 (Command and Scripting Interpreter: Windows Command Shell), identifying how formula injection leads to code execution. When practitioners review their security findings through Casky's 754 mapped skills, the platform would flag suspicious CSV generation patterns, detecting telltale indicators such as cells beginning with '=', '+', '@', or '-' characters that trigger formula execution. Practitioners would see recommendations to implement input validation and output encoding controls, monitor for unusual data exports, and educate users about the dangers of enabling macros or formula execution in downloaded files. The extended reasoning capability helps practitioners understand not just that the vulnerability exists, but the complete attack chain from initial file download through code execution.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-65875. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation