PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-18738 shlinkio CVE debrief

CVE-2026-18738 is a CSV formula injection vulnerability in Shlink versions 5.0.0 through 5.1.5. An unauthenticated remote attacker can plant spreadsheet formulas into exported visit data by supplying malicious values in User-Agent, Referer, or request path headers. When an administrator opens the exported CSV file in a spreadsheet application, the formulas are executed.

Vendor
shlinkio
Product
Shlink
CVSS
MEDIUM 5.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-03
Original CVE updated
2026-09-09
Advisory published
2026-08-03
Advisory updated
2026-09-09

Who should care

Defenders responsible for Shlink installations should assess exposure and prioritize patching. This includes operators, platform administrators, vulnerability management teams, and security teams who manage Shlink deployments. They should verify Shlink versions, apply patches, and monitor for suspicious requests to prevent exploitation.

Why it matters

CVE-2026-18738 is a medium-severity vulnerability in Shlink that allows attackers to plant spreadsheet formulas into exported visit data. Defenders should prioritize verifying Shlink versions and applying patches to prevent exploitation.

  • Potential for malicious CSV files to be executed on administrator's client machines
  • Possible unauthorized access to sensitive data through exported CSV files
  • Risk of exploitation through unauthenticated requests

Technical summary

The vulnerability exists in Shlink versions 5.0.0 through 5.1.5. An attacker can supply malicious values in User-Agent, Referer, or request path headers to plant spreadsheet formulas into exported visit data. This allows unauthenticated remote attackers to plant spreadsheet formulas into exported visit data by supplying malicious values. The formulas are executed on an administrator's client machine when the exported CSV file is opened in a spreadsheet application that evaluates formulas. Defenders should prioritize verifying Shlink versions and applying patches to prevent exploitation.

Defensive priority

Defenders should prioritize verifying Shlink versions and applying patches to prevent exploitation.

Recommended defensive actions

  • Verify Shlink versions and apply patches
  • Restrict access to exported CSV files
  • Monitor for suspicious requests
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions, retest remediated assets
  • Review the supplied official advisory or CVE record

Evidence notes

The vulnerability allows attackers to craft a single unauthenticated request against any short URL to embed DDE or WEBSERVICE formula payloads into CSV cells. The formulas are executed on an administrator's client machine when the exported CSV file is opened. This issue is confirmed in Shlink versions 5.0.0 through 5.1.5, and defenders should verify the version and apply patches. The exploit involves supplying malicious values in User-Agent, Referer, or request path headers beginning with formula-triggering characters such as =, +, -,

Sources and references

Verified primary and authoritative sources

  • CVE-2026-18738 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-18738

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-18738 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18738

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.