eladmin <=2.7 is vulnerable to CSV Injection in the exception log download module.
"2026-04-12T13:53:05Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-22978.json"
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"301195117098250310172124194590346395928",
"22735469467028449368033316264584261200",
"246837469930884708434613466488157158037",
"66397763688500589790082899361649109567",
"176562378080634361508019743747316463372",
"46848041610301684406544023377728611716",
"273172363772874440919731794934771705679",
"206561432641583508997498164058473049155",
"138275494480876189381292757998930319399",
"161078823449046972295844040316590276239",
"134733225621229357472123928446868243532"
]
},
"target": {
"file": "eladmin-common/src/main/java/me/zhengjie/utils/FileUtil.java"
},
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2025-22978-0a4959b6",
"source": "https://github.com/elunez/eladmin/commit/d6a16e9afc0a3b96a56f1a24ed167e1beec6ce2f"
},
{
"digest": {
"length": 621.0,
"function_hash": "306095752260306632210177723131154727610"
},
"target": {
"file": "eladmin-common/src/main/java/me/zhengjie/utils/FileUtil.java",
"function": "downloadExcel"
},
"signature_type": "Function",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2025-22978-39300355",
"source": "https://github.com/elunez/eladmin/commit/d6a16e9afc0a3b96a56f1a24ed167e1beec6ce2f"
}
]