{"id":"PYSEC-2021-866","details":"This affects all versions of package html-to-csv. When there is a formula embedded in a HTML page, it gets accepted without any validation and the same would be pushed while converting it into a CSV file. Through this a malicious actor can embed or generate a malicious link or execute commands via CSV files.","aliases":["CVE-2021-23654","GHSA-fwf6-rw69-hhj4","SNYK-PYTHON-HTMLTOCSV-1582784"],"modified":"2023-11-08T04:05:12.383816Z","published":"2021-11-26T20:15:00Z","references":[{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-PYTHON-HTMLTOCSV-1582784"},{"type":"WEB","url":"https://github.com/hanwentao/html2csv/blob/master/html2csv/converter.py"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fwf6-rw69-hhj4"}],"affected":[{"package":{"name":"html-to-csv","ecosystem":"PyPI","purl":"pkg:pypi/html-to-csv"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.0.1","0.0.2","0.0.3.post1","0.1.0","0.1.1","0.1.2","0.1.3"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/html-to-csv/PYSEC-2021-866.yaml"}}],"schema_version":"1.7.3"}