CSV-Safe gem < 3.0.0 doesn’t filter out special characters which could trigger CSV Injection.
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-28481
- https://github.com/zvory/csv-safe/issues/7
- https://github.com/zvory/csv-safe/pull/8
- https://github.com/WeblateOrg/weblate/commit/d9e136ff228e3760fd6dd7572869ac38e9a81809
- https://hackerone.com/reports/223999
- https://github.com/advisories/GHSA-f55g-x8qq-2569