Executive brief
The json-2-csv library, used to convert data into spreadsheet-compatible files, contains a flaw that allows malicious formulas to be embedded in generated CSVs. Even when the security feature to prevent such injections is enabled, it can be bypassed by adding spaces or using specific character types. If a user opens a manipulated CSV file in a spreadsheet application like Excel, these formulas could execute, potentially leading to data theft or unauthorized information disclosure.
Technical details
The json-2-csv library is vulnerable to CSV Injection (CWE-1236) because its 'preventCsvInjection' security feature uses an insufficient regular expression. The root cause is a regex pattern (/^[=+\-@\t\r]+/g) that only attempts to strip dangerous characters from the absolute start of a string. An attacker can bypass this filter by prefixing a formula with whitespace or using full-width Unicode characters (e.g., '=' instead of '=') which are not caught by the filter but are interpreted as formulas by spreadsheet software like Microsoft Excel or Apple Numbers. This allows for local execution of spreadsheet formulas, which can be leveraged for data exfiltration or information disclosure when a victim opens the generated CSV. The issue is fixed in version 5.5.11.
Affected products
- mrodrig json-2-csv >= 3.15.0, < 5.5.11
Timeline
- 2025-12-06: disclosed: Initial vulnerability report and PoC created by researcher whoamins.
- 2026-05-28: advisory: GitHub Advisory and CVE-2026-9673 published.
- 2026-05-28: patched: Fix released in version 5.5.11.