{"id":"CVE-2022-39217","aliases":["GHSA-634p-93h9-92vh"],"url":"https://o3.security/vulnerability/CVE-2022-39217","summary":"Improper Neutralization of Formula Elements in a CSV File in ghas-to-csv","details":"some-natalie/ghas-to-csv (GitHub Advanced Security to CSV) is a GitHub action which scrapes the GitHub Advanced Security API and shoves it into a CSV. In affected versions this GitHub Action creates a CSV file without sanitizing the output of the APIs. If an alert is dismissed or any other custom field contains executable code / formulas, it might be run when an endpoint opens that CSV file in a spreadsheet program. This issue has been addressed in version `v1`. Users are advised to use `v1` or later. There are no known workarounds for this issue.","published":"2022-09-16T23:20:10Z","modified":"2026-08-27T03:50:46.849399931Z","cvss":{"score":5.8,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"GitHub Actions","name":"some-natalie/ghas-to-csv","fixedVersion":"1"}],"fix":{"url":"https://github.com/some-natalie/ghas-to-csv/commit/d0b521928fa734513b5cd9c7d9d8e09db50e884a","label":"some-natalie/ghas-to-csv@d0b5219"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/39xxx/CVE-2022-39217.json"},{"type":"ADVISORY","url":"https://github.com/some-natalie/ghas-to-csv/security/advisories/GHSA-634p-93h9-92vh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-39217"},{"type":"FIX","url":"https://github.com/some-natalie/ghas-to-csv/commit/d0b521928fa734513b5cd9c7d9d8e09db50e884a"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T03:50:46.849399931Z"}}