Back to CVE List

CVE-2026-9673

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
6.8 / 10
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Vulnerability Description

Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An attacker can inject formulas into CSV files, which execute when the files are opened in spreadsheet applications.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-1236
Source
NVD

External References

Discussion (0)

Add Comment

No comments yet. Be the first!