---
id: CVE-2026-18738
title: >-
  Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection
  vulnerability that allows unauthenticated remote attackers to plant
  spreadsheet formulas into exported visit data by supplying malicious values in
  User-Agent, Referer, o…
summary: >-
  Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection
  vulnerability that allows unauthenticated remote attackers to plant
  spreadsheet formulas into exported visit data by supplying malicious values in
  User-Agent, Referer, o…
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'
cwe:
  - CWE-1236
vendor: shlinkio
product: Shlink
affected:
  - Shlink >= 5.0.0 <= 5.1.5
published: '2026-08-03'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T20:35:08.537'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18738'
references:
  - url: 'https://github.com/shlinkio/shlink'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/theopaid/CSV-formula-injection-in-visit-exports-shlink-'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/shlink-csv-formula-injection-via-visit-export-cli
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-08-04T14:28:31.781240Z'
ingestedAt: '2026-09-14T12:39:02.994Z'
epss: 0.00493
epssPercentile: 0.398
---

## Overview

Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote attackers to plant spreadsheet formulas into exported visit data by supplying malicious values in User-Agent, Referer, or request path headers beginning with formula-triggering characters such as =, +, -, or @. Attackers can craft a single unauthenticated request against any short URL to embed DDE or WEBSERVICE formula payloads into CSV cells, which are then executed on an administrator's client machine when the exported CSV file is opened in a spreadsheet application that evaluates formulas.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
