Medium severity6.8NVD Advisory· Published May 28, 2026· Updated Jul 3, 2026
CVE-2026-9673
CVE-2026-9673
Description
Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An attacker can inject formulas into CSV files, which execute when the files are opened in spreadsheet applications.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
json-2-csvnpm | >= 3.15.0, < 5.5.11 | 5.5.11 |
Affected products
5- osv-coords3 versionspkg:apk/chainguard/opensearch-dashboards-3-dashboards-reportingpkg:apk/wolfi/opensearch-dashboards-3-dashboards-reportingpkg:apk/chainguard/opensearch-dashboards-3-fips-dashboards-reporting
< 3.7.0-r4+ 2 more
- (no CPE)range: < 3.7.0-r4
- (no CPE)range: < 3.7.0-r4
- (no CPE)range: < 3.7.0-r6
- Range: <5.5.11, >=3.15.0
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-g27c-q7cp-mhx6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-9673ghsaADVISORY
- gist.github.com/whoamins/299745a2d36b482b44e9613b78e40613nvdWEB
- github.com/mrodrig/json-2-csv/blob/main/src/json2csv.ts%23L410nvdWEB
- github.com/mrodrig/json-2-csv/commit/0fdd0bb6d0273178cd940afc323ccbce19688229nvdWEB
- security.snyk.io/vuln/SNYK-JS-JSON2CSV-14221326nvdWEB
- security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-17115116nvd
News mentions
0No linked articles in our index yet.