Cross-site scripting vulnerability in CSV+ prior to 0.8.1...
        
  Critical severity
        
          Unreviewed
      
        Published
          Feb 9, 2022 
          to the GitHub Advisory Database
          •
          Updated Feb 3, 2023 
      
  
Description
        Published by the National Vulnerability Database
      Feb 8, 2022 
    
  
        Published to the GitHub Advisory Database
      Feb 9, 2022 
    
  
        Last updated
      Feb 3, 2023 
    
  
Cross-site scripting vulnerability in CSV+ prior to 0.8.1 allows a remote unauthenticated attacker to inject an arbitrary script or an arbitrary OS command via a specially crafted CSV file that contains HTML a tag.
References