CSV Formula Injection Vulnerability in OpenPanel by Openpanel-dev
CVE-2026-108579

2.3LOW

Key Information:

Status
Vendor
CVE Published:
10 October 2026

What is CVE-2026-108579?

OpenPanel, up to version 2.3.0, contains a vulnerability that allows unauthenticated attackers to exploit the system by injecting crafted spreadsheet formulas through the /track endpoint. By manipulating profile IDs with formula syntax such as =HYPERLINK(...), attackers can create tracking events that result in exported cohort CSV files executing these malicious formulas. This behavior leads to potential data exfiltration, wherein adjacent cell data can be compromised, posing significant risks to user data security.

Affected Version(s)

openpanel 0 <= 2.3.0

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HaiND from the Post and Telecommunication Institute of Technology
.