Advisory Database
  • Advisories
  • Dependency Scanning
  1. gem
  2. ›
  3. spree
  4. ›
  5. GHSA-xf4v-w5x5-pv79

GHSA-xf4v-w5x5-pv79: Spree: CSV Formula Injection in Customer Export

June 4, 2026

CSV formula injection (also known as formula injection or CSV injection) affects customer export. User-controlled values customer names, email addresses, and shipping addresses. When an administrator opens a crafted Export in Microsoft Excel or LibreOffice Calc, formulas embedded in user data execute in the context of the administrator’s desktop, potentially exfiltrating data or executing OS commands via DDE (Dynamic Data Exchange).


References

  • github.com/advisories/GHSA-xf4v-w5x5-pv79
  • github.com/spree/spree/releases/tag/v5.2.8
  • github.com/spree/spree/releases/tag/v5.3.6
  • github.com/spree/spree/releases/tag/v5.4.3
  • github.com/spree/spree/security/advisories/GHSA-xf4v-w5x5-pv79

Code Behaviors & Features

Detect and mitigate GHSA-xf4v-w5x5-pv79 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 5.2.0 before 5.2.8, all versions starting from 5.3.0 before 5.3.6, all versions starting from 5.4.0 before 5.4.3

Fixed versions

  • 5.2.8
  • 5.3.6
  • 5.4.3

Solution

Upgrade to versions 5.2.8, 5.3.6, 5.4.3 or above.

Impact 8 HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-1236: Improper Neutralization of Formula Elements in a CSV File

Source file

gem/spree/GHSA-xf4v-w5x5-pv79.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 23 Jun 2026 12:23:19 +0000.