CVE-2017-15879: Keystonejs Keystone
High severity, CVSS 8.8. EPSS: 7.2% chance of exploitation in the next 30 days.
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCSVData.js in KeystoneJS before 4.0.0-beta.7 via a value that is mishandled in a CSV export.
Affected products
- Keystonejs Keystone: up to and including 4.0.0
Published 2017-10-24. Last modified 2026-06-17.