← Back to CVE List
CVE-2026-108579NVD
Vulnerability Summary
OpenPanel through 2.3.0 contains a CSV formula injection vulnerability that allows unauthenticated attackers to embed spreadsheet formulas by supplying crafted profile IDs to the /track endpoint. Attackers can send tracking events with profile IDs like =HYPERLINK(...) matching a cohort, so exported cohort CSVs execute formulas that exfiltrate adjacent cell data.
CVSS v4.0 Base Metrics — Score 2.3 (LOW)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsPresent
Privileges RequiredNone
User InteractionPassive
Confidentiality (Vulnerable System)Low
Integrity (Vulnerable System)Low
Availability (Vulnerable System)None
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 4.2 (MEDIUM)
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredNone
User InteractionRequired
ScopeUnchanged
ConfidentialityLow
IntegrityLow
AvailabilityNone
Affected & Patched Versions
- Openpanel-dev openpanel <= 2.3.0
- Openpanel-dev openpanel 2.3.0
External References
- https://hackmd.io/@haind/openpanel-cohort-csv-formula-injection
- https://github.com/Openpanel-dev/openpanel/blob/7c4d22ae4b6b20fb08eb5c94a0cd3cfebb3d32ca/apps/start/src/utils/csv-download.ts#L1-L29
- https://github.com/Openpanel-dev/openpanel
- https://www.vulncheck.com/advisories/openpanel-through-2.3.0-csv-formula-injection-via-cohort-member-export