CVE-2026-18738
Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote attackers to plant spreadsheet formulas into exported visit data by supplying malicious values in User-Agent, Referer, or request path headers beginning with formula-triggering characters such as =, +, -, or @. Attackers can craft a single unauthenticated request against any short URL to embed DDE or WEBSERVICE formula payloads into CSV cells, which are then executed on an administrator's client machine when the exported CSV file is opened in a spreadsheet application that evaluates formulas.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.38%
- CWE
- CWE-1236
- Published
- 2026-08-03
- Last modified
- 2026-08-04
Affected products
- shlinkio Shlink
Weakness type
Related vulnerabilities
- CVE-2026-86745 — Snipe-IT before 8.7.0 CSV Formula Injection via Location-Scoping Export
- CVE-2026-86742 — Snipe-IT before 8.7.0 CSV Formula Injection via Asset Acceptance Report
- CVE-2026-79971 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-86257 — wger before 2.6 CSV Formula Injection via member export
- CVE-2026-9852 — A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data...
- CVE-2026-76797 — MongoSQL Transition Readiness Tool Improper Neutralization of Formula Elements in Generated Reports
- CVE-2026-56652 — Formula Injection in dool project
- CVE-2026-78209 — exceljs through 4.4.0 CSV Formula Injection via Unescaped Cell Values