T09 · Insecure Skill Coding Practices
- Location
scripts/get_data.py:269- Finding
Spreadsheet Formula Injection in Generated CSV Files
- Content
View full analysis
str: if v is None: return "" if isinstance(v, (dict, list)): return json.dumps(v, ensure_ascii=False) return str(v) ``` ### Technical Analysis Values returned by the remote macroeconomic-data API are converted to strings and written directly into CSV cells. No validation or neutralization is applied to strings beginning with spreadsheet formula markers such as `=`, `+`, `-`, or `@`. Although CSV is nominally a data format, common spreadsheet applications may interpret cells beginning with these characters as formulas. Consequently, a malicious or compromised API response could place an attacker-controlled formula in a generated file. The formula may be evaluated when the user opens the CSV in a compatible spreadsheet application. The vulnerability crosses a trust boundary because remote response content is treated as safe spreadsheet data without output encoding appropriate to the eventual consumer. ### Attack Path 1. An attacker compromises the upstream API, influences a data source consumed by it, or otherwise causes a table value to contain a spreadsheet formula. 2. The API returns a value such as `=HYPERLINK("https://attacker.example/...","Open")` or another applicat ...[truncated 1337 chars]- Remediation
View remediation
str: text = _flatten_value(value) if text.startswith(("=", "+", "-", "@")): return "'" + text return text ``` 2. Use the function for all cells: ```python writer.writerow({ key: _escape_spreadsheet_value(value) for key, value in row.items() }) ``` 3. Consider handling leading tabs, carriage returns, newlines, and whitespace before a formula marker because spreadsheet behavior varies by product. 4. Add automated tests covering values beginning with `=`, `+`, `-`, and `@`, as well as ordinary negative numbers if preserving their numeric type is important. 5. Document that exported files contain untrusted external data and recommend opening them with external-content and macro execution disabled. 6. If consumers require machine-readable numeric values, consider a safer structured format such as JSON or provide a strict CSV mode that validates values against the expected schema and data types. ]]>
