VDB
Sign up
HIGH8.8

GHSA-6494-v9fq-fgq2

Keystone is vulnerable to CSV injection

Quick fix

GHSA-6494-v9fq-fgq2 — keystone: upgrade to the fixed version with the command below.

npm install keystone@4.0.0-beta7

Details

CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCSVData.js in KeystoneJS before 4.0.0-beta.7 via a value that is mishandled in a CSV export.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/keystone
Introduced in: 0Fixed in: 4.0.0-beta7
Fixnpm install keystone@4.0.0-beta7

References