Описание
Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An attacker can inject formulas into CSV files, which execute when the files are opened in spreadsheet applications.
A flaw was found in json-2-csv. An attacker can bypass the preventCsvInjection option to inject malicious formulas into CSV (Comma Separated Values) files. When these manipulated CSV files are opened in spreadsheet applications, the injected formulas can execute, potentially leading to arbitrary code execution or information disclosure.
Отчет
This Moderate vulnerability in json-2-csv allows for CSV Injection due to a bypass in the preventCsvInjection option. While exploitation requires a user to open a specially crafted CSV file in a spreadsheet application, successful attacks could lead to arbitrary code execution or information disclosure. This affects Red Hat Developer Hub and Red Hat Ansible Automation Platform when processing untrusted data that is subsequently exported to CSV and opened by a user.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Self-service automation portal 2 | ansible-automation-platform/bootc-automation-portal-rhel9 | Under investigation | ||
| Red Hat Developer Hub 1.10 | rhdh/rhdh-hub-rhel9 | Fixed | RHSA-2026:36754 | 08.07.2026 |
| Red Hat Developer Hub 1.9 | rhdh/rhdh-hub-rhel9 | Fixed | RHSA-2026:33574 | 30.06.2026 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
6.1 Medium
CVSS3
Связанные уязвимости
Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An attacker can inject formulas into CSV files, which execute when the files are opened in spreadsheet applications.
json-2-csv vulnerable to CSV Injection via the preventCsvInjection optio
6.1 Medium
CVSS3