{"id":"CVE-2022-22121","details":"In NocoDB, versions 0.81.0 through 0.83.8 are affected by CSV Injection vulnerability (Formula Injection). A low privileged attacker can create a new table to inject payloads in the table rows. When an administrator accesses the User Management endpoint and exports the data as a CSV file and opens it, the payload gets executed.","modified":"2026-03-14T11:27:23.094113Z","published":"2022-01-10T16:15:10.243Z","references":[{"type":"FIX","url":"https://github.com/nocodb/nocodb/commit/079e3abe"},{"type":"EVIDENCE","url":"https://www.whitesourcesoftware.com/vulnerability-database/CVE-2022-22121"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nocodb/nocodb","events":[{"introduced":"ff95d8fff8d14d469f107b8be729b774f17e1bf0"},{"last_affected":"aa3348ae164de24e2b93b9f17e8b753ac1b1ff20"},{"fixed":"079e3abe"}],"database_specific":{"versions":[{"introduced":"0.81.0"},{"last_affected":"0.83.8"}]}}],"versions":["0.81.0","0.81.1","0.82.0","0.83.0","0.83.1","0.83.2","0.83.3","0.83.4","0.83.5","0.83.6","0.83.8"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-22121.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}