CVE-2022-39217 is a critical vulnerability affecting the some-natalie/ghas-to-csv GitHub Action, which fails to sanitize output when generating CSV files from GitHub Advanced Security API data. This allows for the injection of executable code or formulas into the CSV, which could be triggered when opened in a spreadsheet program. With a CVSS score of 9.8 (CRITICAL), this vulnerability has a network attack vector, low attack complexity, and can lead to high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1CPE matchmatch criteria | cpe:2.3:a:ghas-to-csv_project:ghas-to-csv:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.