


Perceptive Security
SOC/SIEM Consultancy

Dirsearch 0.4.1 contains a CSV injection vulnerability when using the --csv-report flag that allows attackers to inject formulas through redirected endpoints. A…
Published:
26 januari 2026 om 23:00:00
Alert date:
27 januari 2026 om 17:08:00
Source:
nvd.nist.gov
Security Tools
CVE-2021-47901 affects Dirsearch version 0.4.1, a web directory enumeration tool. The vulnerability exists in the CSV reporting functionality (--csv-report flag) and allows for CSV injection attacks. Attackers can exploit this by crafting malicious server redirects that contain comma-separated paths with Excel formulas. When the tool generates CSV reports, these malicious formulas are injected into the output file. This can lead to formula execution when the CSV report is opened in spreadsheet applications like Excel. The vulnerability demonstrates how output formatting features in security tools can become attack vectors themselves.
Technical details
Mitigation steps:
Affected products:
Dirsearch
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2021-47901
https://github.com/maurosoria/dirsearch
https://www.exploit-db.com/exploits/49370
https://www.vulncheck.com/advisories/dirsearch-csv-injection
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
