T09 · Insecure Skill Coding Practices
- Location
index.ts:322- Finding
CSV Formula and Structure Injection in Report Export
- Content
View full analysis
[ p.materialId, p.impressions.toString(), p.clicks.toString(), (p.ctr * 100).toFixed(2) + "%", p.conversions.toString(), (p.cvr * 100).toFixed(2) + "%", p.cost.toFixed(2), p.revenue.toFixed(2), p.roas.toFixed(2) ]); const csv = [headers, ...rows].map(row => row.join(",")).join("\n"); ``` ### Technical Analysis The CSV exporter inserts `p.materialId` directly into a comma-separated row without CSV escaping or spreadsheet-formula neutralization. The material identifier originates from the required `materialId` argument of the `analytics ingest` command and can therefore contain attacker-controlled content. A material identifier beginning with `=`, `+`, `-`, or `@` may be interpreted as a formula when the exported file is opened in spreadsheet software. Depending on the spreadsheet application and its security settings, such formulas may initiate external requests, expose contextual information, or present deceptive content. The implementation also fails to quote fields containing commas, double quotes, carriage returns, or line feeds. An attacker can consequently create additional cells or records, corrupt the report structure, and inject misleading report content. ### Attack Path 1. An attacker or untrusted data source invokes the analytics ingestion command with a malicious `materialId`, such as a spreadsheet formula or a value containing commas and newlines. 2. The application stores the identifier in the in-memory performance map without validation or normalization. 3. A report is generated while the malicious material is included among `topPerformers`. 4. A user invoke ...[truncated 1131 chars]- Remediation
View remediation
