CVE-2026-108579: OpenPanel through 2.3.0 CSV Formula Injection via Cohort Member Export
OpenPanel through 2.3.0 contains a CSV formula injection vulnerability that allows unauthenticated attackers to embed spreadsheet formulas by supplying crafted profile IDs to the /track endpoint. Attackers can send tracking events with profile IDs like =HYPERLINK(...) matching a cohort, so exported cohort CSVs execute formulas that exfiltrate adjacent cell data.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Organizations using OpenPanel through 2.3.0 are exposed when cohort member data is exported to CSV and opened in spreadsheet software that evaluates formulas. The attacker does not need an account, but a user must export and open a cohort CSV for the formula to execute.
What must an attacker do to exploit it?
An attacker must submit tracking events to the /track endpoint with a crafted profile ID containing a spreadsheet formula, such as =HYPERLINK(...). The crafted profile ID must match a cohort that is later exported.
What can happen when a malicious export is opened?
The embedded formula can execute in the spreadsheet application and exfiltrate data from adjacent cells. The described impact is limited to confidentiality and integrity; no availability impact is stated.