CVE-2022-28481: Csv-Safe Project Csv-Safe
Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.
CSV-Safe gem < 3.0.0 doesn't filter out special characters which could trigger CSV Injection.
Affected products
- Csv-Safe Project Csv-Safe: before 3.0.0 (fixed in 3.0.0)
Published 2022-05-01. Last modified 2026-06-17.