Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An attacker can inject formulas into CSV files, which execute when the files are opened in spreadsheet applications.
Metrics
Affected Vendors & Products
References
History
Thu, 28 May 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | CSV Injection Vulnerability in json-2-csv Package via PreventCsvInjection Option |
Thu, 28 May 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An attacker can inject formulas into CSV files, which execute when the files are opened in spreadsheet applications. | |
| Weaknesses | CWE-1236 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2026-05-28T05:00:02.387Z
Reserved: 2026-05-27T05:35:32.761Z
Link: CVE-2026-9673
No data.
Status : Received
Published: 2026-05-28T06:16:29.147
Modified: 2026-05-28T06:16:29.147
Link: CVE-2026-9673
No data.
OpenCVE Enrichment
Updated: 2026-05-28T07:30:11Z