T09 · Insecure Skill Coding Practices
- Location
scripts/csv_to_excel.py:35- Finding
Spreadsheet Formula Injection in CSV-to-Excel Conversion
- Content
View full analysis
31: sheet_name = sheet_name[:31] df.to_excel(out, sheet_name=sheet_name, index=False, engine="openpyxl") print(f"Converted {len(df)} rows -> {out} (sheet: {sheet_name})") return paths = [Path(p) for p in args.inputs] for p in paths: if not p.exists(): print(f"File does not exist: {p}", file=sys.stderr) sys.exit(1) with pd.ExcelWriter(out, engine="openpyxl") as writer: for path in paths: df = pd.read_csv(path, encoding=args.encoding, sep=args.sep) name = path.stem if len(name) > 31: name = name[:31] df.to_excel(writer, sheet_name=name, index=False) ``` ### Technical Analysis CSV values are transferred directly into an XLSX workbook without checking whether string values begin with spreadsheet formula metacharacters. In particular, a value beginning with `=` can be stored as an active formula by the Excel-writing engine. Values beginning with `+`, `-`, or `@` should also be treated as potentially dangerous for compatibility with spreadsheet clients and downstream conversions. The input file is therefore treated as trusted executable spreadsheet content rather than untrusted data. An attacker who controls a CSV cell can introduce formulas containing hyperlinks, external workbook references, web-service calls, or other client-supported formula features. ### Attack Path 1. An attacker supplies a CSV file containing a crafted value, such as an external-reference or hyperlink formula ...[truncated 1320 chars]- Remediation
View remediation
