json-2-csv: json-2-csv: CSV Injection vulnerability allows arbitrary code execution via `preventCsvInjection` bypass.
Published May 28, 2026
7.0
HIGHCVSS 4.0
EPSS 0.24%
Description
Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An attacker can inject formulas into CSV files, which execute when the files are opened in spreadsheet applications.
Affected products
- Vendor n/a Product Json-2-Csv Defaultn/a
- Version 3.15.0StatusaffectedConstraints<5.5.11
- Version
- Vendor n/a Product Org.webjars.npm:json-2-Csv Defaultn/a
- Version 0StatusaffectedConstraints<*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Json-2-Csv | n/a |
| ||||||
| n/a | Org.webjars.npm:json-2-Csv | n/a |
|
No data.
No data.
Red Hat Developer Hub 1.10
rhdh/rhdh-hub-rhel9:1783448184
Fixed · RHSA-2026:36754
Red Hat Developer Hub 1.9
rhdh/rhdh-hub-rhel9:1782761244
Fixed · RHSA-2026:33574
Self-service automation portal 2
ansible-automation-platform/bootc-automation-portal-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Developer Hub 1.10 | rhdh/rhdh-hub-rhel9:1783448184 | Fixed | RHSA-2026:36754 |
| Red Hat Developer Hub 1.9 | rhdh/rhdh-hub-rhel9:1782761244 | Fixed | RHSA-2026:33574 |
| Self-service automation portal 2 | ansible-automation-platform/bootc-automation-portal-rhel9 | Not affected | n/a |
json-2-csv
npm
Introduced 3.15.0 Fixed 5.5.11
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | json-2-csv | 3.15.0 | 5.5.11 |
Remediation
Red Hat statement
This Moderate vulnerability in `json-2-csv` allows for CSV Injection due to a bypass in the `preventCsvInjection` option. While exploitation requires a user to open a specially crafted CSV file in a spreadsheet application, successful attacks could lead to arbitrary code execution or information disclosure. This affects Red Hat Developer Hub and Red Hat Ansible Automation Platform when processing untrusted data that is subsequently exported to CSV and opened by a user.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Metrics
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
2 other sources (CVE.org, NVD) ▾
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
2 other sources (Red Hat, CVE.org) ▾
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N/E:P
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed May 28, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
May–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.24% (0.00236) | 13.30th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.17% (0.00166) | 6.14th | v5 (v2026.06.15) |
| May 28, 2026 | 0.03% (0.00025) | 7.67th | v4 (v2025.03.14) |
References (10)
- https://access.redhat.com/security/cve/CVE-2026-9673 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2482486 Issue Tracking
- https://gist.github.com/whoamins/299745a2d36b482b44e9613b78e40613
- https://github.com/advisories/GHSA-g27c-q7cp-mhx6 Advisory
- https://github.com/mrodrig/json-2-csv/blob/main/src/json2csv.ts%23L410
- https://github.com/mrodrig/json-2-csv/commit/0fdd0bb6d0273178cd940afc323ccbce19688229
- https://nvd.nist.gov/vuln/detail/CVE-2026-9673
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-17115116
- https://security.snyk.io/vuln/SNYK-JS-JSON2CSV-14221326
- https://www.cve.org/CVERecord?id=CVE-2026-9673
Change history (0)
No recorded changes yet.