ERPGo SaaS 3.9 contains a CSV injection vulnerability that allows authenticated attackers to execute arbitrary code by injecting formula payloads into vendor name fields. Attackers can add malicious formulas like =10+20+cmd|' /C calc'!A0 in the vendor creation form, which execute when the exported CSV file is opened in spreadsheet applications.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2023-54348 is a CSV injection vulnerability affecting ERPGo SaaS version 3.9 that enables authenticated attackers to execute arbitrary code through malicious formula payloads. By injecting formulas like =10+20+cmd|' /C calc'!A0 into vendor name fields during vendor creation, attackers can achieve remote code execution when victims open exported CSV files in spreadsheet applications like Microsoft Excel or Google Sheets. This vulnerability matters because ERPGo is a SaaS platform handling enterprise resource planning—critical business infrastructure—and the attack requires only basic authentication access, making it exploitable by insiders or attackers with compromised credentials. Organizations using ERPGo 3.9 are directly affected, particularly those with vendor management workflows involving CSV exports.
Casky's skills mapped to MITRE ATT&CK technique T1059.003 (Command and Scripting Interpreter: Windows Command Shell) would detect attack patterns associated with this vulnerability by identifying suspicious formula injection attempts in structured data fields and recognizing command execution payloads embedded in CSV-exportable content. Practitioners using Casky's Claude AI-powered analysis would see findings highlighting: (1) anomalous formula syntax in vendor name inputs that deviate from legitimate data patterns, (2) detection of command execution operators (cmd, pipe characters, shell metacharacters) within fields designed for text-only input, and (3) correlation between vendor creation activities and subsequent CSV export operations that could trigger code execution. Extended reasoning would connect these indicators to the broader attack chain, surfacing that spreadsheet formula injection represents a post-export execution vector distinct from typical injection attacks, enabling security teams to implement compensating controls around CSV handling and spreadsheet application hardening.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2023-54348. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation