T09 · Insecure Skill Coding Practices
- Location
scripts/zabbix_cron.py:292- Finding
Spreadsheet Formula Injection Through Zabbix-Controlled Fields
- Content
View full analysis
Vulnerability Details
File Location:
scripts/zabbix_cron.py, lines 292-306
Vulnerability Type: CSV/XLSX formula injection
Risk Level: HighVulnerable Code
python with open(CSV_PATH, "w", newline="", encoding="utf-8-sig") as f: writer = csv.writer(f) writer.writerow(["主机组", "主机名", "IP", "内存总量(GB)", "内存可用(GB)", "内存占用率(%)", "CPU占用率(%)"]) for r in rows: writer.writerow([ r["group"], r["name"], r["ip"], f"{r['mem_total_gb']:.1f}" if r['mem_total_gb'] is not None else "N/A", f"{r['mem_avail_gb']:.1f}" if r['mem_avail_gb'] is not None else "N/A", f"{r['mem_used_pct']:.1f}" if r['mem_used_pct'] is not None else "N/A", f"{r['cpu_pct']:.1f}" if r['cpu_pct'] is not None else "N/A", ])The same untrusted host and group values are also assigned directly to XLSX cells during report generation, and both generated files are subsequently attached to an email:
python atts = [f for f in [XLSX_PATH, CSV_PATH] if os.path.exists(f)] send_email(subject, html, atts)Equivalent behavior is present in
scripts/zabbix_monitor.pyandreferences/zabbix_cron.py.Technical Analysis
The fields
group,name, andiporiginate from Zabbix API responses and are written into spreadsheet files without neutralizing spreadsheet control characters. Values beginning with=,+,-, or@may be interpreted as formulas when the CSV or XLSX report is opened in spreadsheet software.Quoting a field with Python's
csv.writerdoes not prevent formula interpretation. For XLSX output, assigning a string beginning with=throughopenpyxlmay explicitly create a formula cell.An attacker who can create or rename a Zabbix host, alter a visible host name, or influence host-group names can therefore persist a spreadsheet payload in the generated report. Depending on spreadsheet software and security settings, formu ...[truncated 1654 chars]
- Remediation
View remediation
Remediation Suggestions
- Neutralize every externally sourced spreadsheet string before writing CSV or XLSX output.
- Prefix values beginning with
=,+,-,@, tab, carriage return, or line feed with an apostrophe. - For XLSX output, force untrusted values to the string data type instead of allowing formula inference.
- Apply the same protection to host names, host groups, addresses, instance identifiers, service names, and any future metadata columns.
- Consider using a centralized helper:
python def safe_spreadsheet_text(value): text = str(value) if text.startswith(("=", "+", "-", "@", "\t", "\r", "\n")): return "'" + text return text- Escape values separately for HTML email output using
html.escape; spreadsheet neutralization does not protect HTML. - Add automated tests containing formula prefixes and verify that generated XLSX cells have string type rather than formula type.
- Apply the fix consistently to
scripts/zabbix_cron.py,scripts/zabbix_monitor.py, andreferences/zabbix_cron.py.
