CSV -> import on web app -> SQLi
Malicious input -> CSV download from web app -> Excel -> formula -> sneaky data exfil
CSV -> JS -> import into web app XSS (in places no other XSS existed because of the data)
CSV import -> weird CSV header -> arbitrary data loading (headers were column names.... Schema injection .. like SQLi only more hilarious
Point is apps and devs can have blind spots (knowledge gaps) or just not think of a CSV import or export like other functionality.