
CVE-2026-18738 Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote attackers to plant spreadsheet formulas into expo… https://www.cve.org/CVERecord?id=CVE-2026-18738
Post summary
The tweet announces the discovery of CVE-2026-18738, a CSV formula injection that allows unauthenticated remote exploitation in Shlink 5.x. No proof‑of‑concept, exploit code, patch, or active exploitation details are provided.

