CVE-2026-9673 - CERT CVE
ID CVE-2026-9673
Sažetak Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An attacker can inject formulas into CSV files, which execute when the files are opened in spreadsheet applications.
Reference
CVSS
Base: 6.8
Impact: 4.2
Exploitability:2.5
Pristup
VektorSloženostAutentikacija
LOCAL LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
HIGH LOW NONE
CVSS vektor CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Zadnje važnije ažuriranje 29-05-2026 - 02:47
Objavljeno 28-05-2026 - 06:16