CVE-2026-108579
Deferred Deferred - Pending Action

CSV Formula Injection in OpenPanel Tracking Endpoint

Vulnerability report for CVE-2026-108579, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

OpenPanel through 2.3.0 contains a CSV formula injection vulnerability that allows unauthenticated attackers to embed spreadsheet formulas by supplying crafted profile IDs to the /track endpoint. Attackers can send tracking events with profile IDs like =HYPERLINK(...) matching a cohort, so exported cohort CSVs execute formulas that exfiltrate adjacent cell data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Openpanel-dev openpanel 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1236 The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

OpenPanel through version 2.3.0 has a CSV formula injection vulnerability. Attackers can send tracking events with crafted profile IDs containing spreadsheet formulas (like =HYPERLINK(...)) to the /track endpoint. When a cohort is exported to CSV and opened in a spreadsheet application, the formulas execute, potentially exfiltrating data from adjacent cells.

Detection Guidance

To detect this vulnerability, monitor network traffic for tracking events with profile IDs starting with formula triggers like =, +, -, or @ sent to the /track endpoint. Check exported cohort CSVs for injected formulas in profile IDs. Inspect the escapeCsvValue function in csv-download.ts for missing sanitization of formula prefixes.

Impact Analysis

This vulnerability allows unauthenticated attackers to inject malicious formulas into exported CSVs. If you open the CSV in a spreadsheet program that evaluates formulas, the attacker could steal data from your spreadsheet or perform unauthorized actions. The impact depends on the spreadsheet application's settings and requires user interaction to open the file.

Compliance Impact

The vulnerability could indirectly impact compliance with GDPR and HIPAA by enabling data exfiltration through CSV formula execution. If exported cohort CSVs contain malicious formulas, attackers might access or leak sensitive user data when the file is opened in a spreadsheet application. This could violate GDPR's data protection principles or HIPAA's confidentiality requirements, depending on the data processed by OpenPanel.

Mitigation Strategies

Update OpenPanel to a patched version where escapeCsvValue prefixes cell values starting with formula triggers with a single quote. Alternatively, modify the function manually to neutralize =, +, -, and @ prefixes before CSV quoting. Ensure users avoid opening exported CSVs in spreadsheet applications that evaluate formulas.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108579. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart