---
id: CVE-2022-2112
aliases:
  - GHSA-9hx5-jmxv-x44q
  - PYSEC-2026-824
title: CSV Injection in inventree
summary: CSV Injection in inventree
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
vendor: inventree
product: inventree
ecosystem: pip
affected:
  - inventree < 0.7.2
patched:
  - inventree 0.7.2
published: '2022-06-18'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-9hx5-jmxv-x44q'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2022-2112'
  - url: >-
      https://github.com/inventree/inventree/commit/26bf51c20a1c9b3130ac5dd2e17649bece5ff84f
  - url: 'https://github.com/inventree/InvenTree'
  - url: 'https://huntr.dev/bounties/e57c36e7-fa39-435f-944a-3a52ee066f73'
tags:
  - osv
  - pip
epss: 0.01283
epssPercentile: 0.68843
ingestedAt: '2026-07-08T18:25:48.025Z'
---

## Overview

Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2.

## Affected packages

- `inventree < 0.7.2`

## Remediation

Upgrade to a patched release:

- `inventree 0.7.2`
