Impact
Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection flaw (CWE‑1236) that lets an unauthenticated attacker embed spreadsheet formulas in visit export data by inserting malicious header values beginning with characters such as =, +, -, or @ in the User‑Agent, Referer, or request path headers. When an exported CSV file is opened in a spreadsheet application that evaluates formulas, the injected DDE or WEBSERVICE payloads execute on the client, potentially allowing the attacker to run code or exfiltrate data.
Affected Systems
The affected product is Shlink by shlinkio. Vulnerable releases span from 5.0.0 up to and including 5.1.5; any installation of Shlink in that range that exposes CSV visit exports is at risk.
Risk and Exploitability
The vulnerability scores 5.1 on CVSS, indicating moderate severity, and its EPSS score is not available. It is not listed in CISA’s KEV catalog. Exploitation requires an unauthenticated HTTP request to a short URL that triggers the visit export; the attacker supplies the malicious header values, and then a victim who opens the resulting CSV in a spreadsheet that automatically evaluates formulas can be compromised. The risk is heightened when administrators frequently import exported data into spreadsheet software that enables formula execution.
OpenCVE Enrichment