Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An attacker can inject formulas into CSV files, which execute when the files are opened in spreadsheet applications.
References
Configurations
No configuration.
History
28 May 2026, 06:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-28 06:16
Updated : 2026-05-29 02:47
NVD link : CVE-2026-9673
Mitre link : CVE-2026-9673
CVE.ORG link : CVE-2026-9673
JSON object : View
Products Affected
No product.
CWE
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
