Description
If a malformed data is input to the affected product, a CSV file downloaded from the affected product may contain such malformed data. When a victim user download and open such a CSV file, the embedded code may be executed in the user's environment. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well.
Scores
CVSS v3
6.5
EPSS
0.0002
EPSS Percentile
3.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1236
Status
published
Products (14)
Six Apart Ltd./Movable Type (Cloud Edition)
8.8.1 (8 series)
Six Apart Ltd./Movable Type (Cloud Edition)
9.0.5 (9 series)
Six Apart Ltd./Movable Type (Software Edition)
8.0.2 to 8.0.8 (8.0 series)
Six Apart Ltd./Movable Type (Software Edition)
8.8.0 to 8.8.1 (8.8 series)
Six Apart Ltd./Movable Type (Software Edition)
9.0.4 to 9.0.5 (9.0 series)
Six Apart Ltd./Movable Type Advanced (Software Edition)
8.0.2 to 8.0.8 (8.0 series)
Six Apart Ltd./Movable Type Advanced (Software Edition)
8.8.0 to 8.8.1 (8.8 series)
Six Apart Ltd./Movable Type Advanced (Software Edition)
9.0.4 to 9.0.5 (9.0 series)
Six Apart Ltd./Movable Type Premium (Advanced Edition) (Software Edition)
2.13 and earlier (MTP 2 series)
Six Apart Ltd./Movable Type Premium (Advanced Edition) (Software Edition)
9.0.4 (MTP 9.0 series)
... and 4 more
Published
Feb 04, 2026
Tracked Since
Feb 18, 2026