csv-stringify is vulnerable to Improper Neutralization of Formula Elements in a CSV File
80
High Risk
Affected versions of this package are vulnerable to CSV injection due to insufficient escaping logic in the escape_formulas parameter. This feature attempts to neutralize formula-triggering, but fails to cover all dangerous characters or multi-byte Unicode sequences. An attacker could exploit this by crafting payloads starting with unhandled characters (such as line feeds or specially formatted Unicode), which, when imported into spreadsheet applications, execute arbitrary commands, exfiltrate data, or manipulate local files via crafted formulas like =cmd|'/C calc'!A0 hidden in exported CSV cells.
You are affected if you are using a version that falls within the vulnerable range.
csv-stringify is vulnerable to Improper Neutralization of Formula Elements in a CSV File in versions 6.1.0 - 6.5.2.
Upgrade the csv-stringify library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant