Vulnerability Description
Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote attackers to plant spreadsheet formulas into exported visit data by supplying malicious values in User-Agent, Referer, or request path headers beginning with formula-triggering characters such as =, +, -, or @. Attackers can craft a single unauthenticated request against any short URL to embed DDE or WEBSERVICE formula payloads into CSV cells, which are then executed on an administrator's client machine when the exported CSV file is opened in a spreadsheet application that evaluates formulas.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/shlinkio/shlink
- https://github.com/theopaid/CSV-formula-injection-in-visit-exports-shlink-
- https://www.vulncheck.com/advisories/shlink-csv-formula-injection-via-visit-expo
FAQ
What is CVE-2026-18738?
CVE-2026-18738 is a vulnerability with a CVSS score of 4.7 (MEDIUM). Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote attackers to plant spreadsheet formulas into exported visit data by supplying malic...
How severe is CVE-2026-18738?
CVE-2026-18738 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-18738?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.