PatchSiren cyber security CVE debrief
CVE-2026-18738 shlinkio CVE debrief
CVE-2026-18738 is a CSV formula injection vulnerability in Shlink versions 5.0.0 through 5.1.5. An unauthenticated remote attacker can plant spreadsheet formulas into exported visit data by supplying malicious values in User-Agent, Referer, or request path headers. When an administrator opens the exported CSV file in a spreadsheet application, the formulas are executed.
- Vendor
- shlinkio
- Product
- Shlink
- CVSS
- MEDIUM 5.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-03
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-03
- Advisory updated
- 2026-09-09
Who should care
Defenders responsible for Shlink installations should assess exposure and prioritize patching. This includes operators, platform administrators, vulnerability management teams, and security teams who manage Shlink deployments. They should verify Shlink versions, apply patches, and monitor for suspicious requests to prevent exploitation.
Why it matters
CVE-2026-18738 is a medium-severity vulnerability in Shlink that allows attackers to plant spreadsheet formulas into exported visit data. Defenders should prioritize verifying Shlink versions and applying patches to prevent exploitation.
- Potential for malicious CSV files to be executed on administrator's client machines
- Possible unauthorized access to sensitive data through exported CSV files
- Risk of exploitation through unauthenticated requests
Technical summary
The vulnerability exists in Shlink versions 5.0.0 through 5.1.5. An attacker can supply malicious values in User-Agent, Referer, or request path headers to plant spreadsheet formulas into exported visit data. This allows unauthenticated remote attackers to plant spreadsheet formulas into exported visit data by supplying malicious values. The formulas are executed on an administrator's client machine when the exported CSV file is opened in a spreadsheet application that evaluates formulas. Defenders should prioritize verifying Shlink versions and applying patches to prevent exploitation.
Defensive priority
Defenders should prioritize verifying Shlink versions and applying patches to prevent exploitation.
Recommended defensive actions
- Verify Shlink versions and apply patches
- Restrict access to exported CSV files
- Monitor for suspicious requests
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions, retest remediated assets
- Review the supplied official advisory or CVE record
Evidence notes
The vulnerability allows attackers to craft a single unauthenticated request against any short URL to embed DDE or WEBSERVICE formula payloads into CSV cells. The formulas are executed on an administrator's client machine when the exported CSV file is opened. This issue is confirmed in Shlink versions 5.0.0 through 5.1.5, and defenders should verify the version and apply patches. The exploit involves supplying malicious values in User-Agent, Referer, or request path headers beginning with formula-triggering characters such as =, +, -,
Sources and references
Verified primary and authoritative sources
-
CVE-2026-18738 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-18738
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-18738 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18738
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/shlinkio/shlink
-
Source reference
Unverified legacy reference
URL: https://github.com/theopaid/CSV-formula-injection-in-visit-exports-shlink-
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/shlink-csv-formula-injection-via-visit-export-cli
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.