Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-9673

Опубликовано: 28 мая 2026
Источник: redhat
CVSS3: 6.1

Описание

Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An attacker can inject formulas into CSV files, which execute when the files are opened in spreadsheet applications.

A flaw was found in json-2-csv. An attacker can bypass the preventCsvInjection option to inject malicious formulas into CSV (Comma Separated Values) files. When these manipulated CSV files are opened in spreadsheet applications, the injected formulas can execute, potentially leading to arbitrary code execution or information disclosure.

Отчет

This Moderate vulnerability in json-2-csv allows for CSV Injection due to a bypass in the preventCsvInjection option. While exploitation requires a user to open a specially crafted CSV file in a spreadsheet application, successful attacks could lead to arbitrary code execution or information disclosure. This affects Red Hat Developer Hub and Red Hat Ansible Automation Platform when processing untrusted data that is subsequently exported to CSV and opened by a user.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Self-service automation portal 2ansible-automation-platform/bootc-automation-portal-rhel9Under investigation
Red Hat Developer Hub 1.10rhdh/rhdh-hub-rhel9FixedRHSA-2026:3675408.07.2026
Red Hat Developer Hub 1.9rhdh/rhdh-hub-rhel9FixedRHSA-2026:3357430.06.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1236
https://bugzilla.redhat.com/show_bug.cgi?id=2482486json-2-csv: json-2-csv: CSV Injection vulnerability allows arbitrary code execution via `preventCsvInjection` bypass.

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
nvd
2 месяца назад

Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An attacker can inject formulas into CSV files, which execute when the files are opened in spreadsheet applications.

CVSS3: 6.8
github
2 месяца назад

json-2-csv vulnerable to CSV Injection via the preventCsvInjection optio

6.1 Medium

CVSS3