CSV Injection Vulnerability in json-2-csv by mrodrig
CVE-2026-9673
7HIGH
What is CVE-2026-9673?
Versions of the json-2-csv package prior to 5.5.11 are susceptible to a CSV Injection vulnerability caused by a bypass of the preventCsvInjection option. This vulnerability allows attackers to inject malicious formulas into CSV files. Upon opening these files in spreadsheet applications, the formulas can execute unintended actions, potentially leading to data leakage or manipulation.
Affected Version(s)
json-2-csv 3.15.0 < 5.5.11
