CVE-2026-9673
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7epss 0.2%
exploitation probability
0.2%top 94% of all CVEs
observed exploitation
nono source reports it
Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An attacker can inject formulas into CSV files, which execute when the files are opened in spreadsheet applications.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
References
https://gist.github.com/whoamins/299745a2d36b482b44e9613b78e40613https://github.com/mrodrig/json-2-csv/blob/main/src/json2csv.ts%23L410https://github.com/mrodrig/json-2-csv/commit/0fdd0bb6d0273178cd940afc323ccbce19688229https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-17115116https://security.snyk.io/vuln/SNYK-JS-JSON2CSV-14221326