{
  "threat_severity" : "Moderate",
  "public_date" : "2026-05-28T05:00:02Z",
  "bugzilla" : {
    "description" : "json-2-csv: json-2-csv: CSV Injection vulnerability allows arbitrary code execution via `preventCsvInjection` bypass.",
    "id" : "2482486",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2482486"
  },
  "cvss3" : {
    "cvss3_base_score" : "6.1",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-1236",
  "details" : [ "Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An attacker can inject formulas into CSV files, which execute when the files are opened in spreadsheet applications.", "A flaw was found in json-2-csv. An attacker can bypass the `preventCsvInjection` option to inject malicious formulas into CSV (Comma Separated Values) files. When these manipulated CSV files are opened in spreadsheet applications, the injected formulas can execute, potentially leading to arbitrary code execution or information disclosure." ],
  "statement" : "This Moderate vulnerability in `json-2-csv` allows for CSV Injection due to a bypass in the `preventCsvInjection` option. While exploitation requires a user to open a specially crafted CSV file in a spreadsheet application, successful attacks could lead to arbitrary code execution or information disclosure. This affects Red Hat Developer Hub and Red Hat Ansible Automation Platform when processing untrusted data that is subsequently exported to CSV and opened by a user.",
  "affected_release" : [ {
    "product_name" : "Red Hat Developer Hub 1.10",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36754",
    "cpe" : "cpe:/a:redhat:rhdh:1.10::el9",
    "package" : "rhdh/rhdh-hub-rhel9:1783448184"
  }, {
    "product_name" : "Red Hat Developer Hub 1.9",
    "release_date" : "2026-06-30T00:00:00Z",
    "advisory" : "RHSA-2026:33574",
    "cpe" : "cpe:/a:redhat:rhdh:1.9::el9",
    "package" : "rhdh/rhdh-hub-rhel9:1782761244"
  } ],
  "package_state" : [ {
    "product_name" : "Self-service automation portal 2",
    "fix_state" : "Under investigation",
    "package_name" : "ansible-automation-platform/bootc-automation-portal-rhel9",
    "cpe" : "cpe:/a:redhat:ansible_portal:2"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-9673\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-9673\nhttps://gist.github.com/whoamins/299745a2d36b482b44e9613b78e40613\nhttps://github.com/mrodrig/json-2-csv/blob/main/src/json2csv.ts%23L410\nhttps://github.com/mrodrig/json-2-csv/commit/0fdd0bb6d0273178cd940afc323ccbce19688229\nhttps://security.snyk.io/vuln/SNYK-JS-JSON2CSV-14221326" ],
  "name" : "CVE-2026-9673",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}