{"id":"GHSA-xgwh-cgv9-783v","summary":"Ghost allows CSV Injection during member CSV export","details":"Ghost before 5.82.0 allows CSV Injection during a member CSV export.","aliases":["BIT-ghost-2024-34448","CVE-2024-34448"],"modified":"2026-03-11T07:49:50.676240Z","published":"2024-05-22T18:30:40Z","database_specific":{"cwe_ids":["CWE-74"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-05-22T19:30:01Z","nvd_published_at":"2024-05-22T16:15:10Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-34448"},{"type":"WEB","url":"https://github.com/TryGhost/Ghost/commit/de668e7950a019a204b2df0c84596ea0fa32cce6"},{"type":"PACKAGE","url":"https://github.com/TryGhost/Ghost"},{"type":"WEB","url":"https://github.com/phulelouch/CVEs/blob/main/CVE-2024-34448.md"}],"affected":[{"package":{"name":"@tryghost/members-csv","ecosystem":"npm","purl":"pkg:npm/%40tryghost/members-csv"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"5.82.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-xgwh-cgv9-783v/GHSA-xgwh-cgv9-783v.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}