T09 · Insecure Skill Coding Practices
- Location
scripts/permit-pipeline.js:157- Finding
Spreadsheet Formula Injection in Generated CSV Files
- Content
View full analysis
`"${l.business}","${l.permitType}","${l.address}","${l.city}","${l.email || ''}","${l.status}","${l.date}"` ).join('\n'); fs.writeFileSync(filename, header + rows); console.log(`\n💾 Saved ${leads.length} leads to ${filename}`); } ``` ### Technical Analysis The application exports remotely sourced permit information and search-derived email addresses directly into CSV cells without neutralizing spreadsheet formula prefixes. Values beginning with `=`, `+`, `-`, or `@` may be interpreted as formulas when the resulting file is opened in spreadsheet software. Wrapping a value in double quotes does not prevent formula evaluation. The implementation also fails to escape embedded double quotes, carriage returns, and line feeds, allowing malicious data to alter the logical structure of the CSV file. The affected fields include: - Business name - Permit type - Address - City - Email address - Permit date These values originate wholly or partly from external government pages and Brave Search results and therefore must not be treated as trusted spreadsheet content. ### Attack Path 1. An attacker causes a formula-like string to appear in a permit record or another externally retrieved field, such as a business name beginning with `=HYPERLINK(...)`. 2. The pipeline downloads and parses the malicious value. 3. `saveToCSV` inserts the value into the generated CSV without formula neutralization or correct field escaping. 4. An operator opens the CSV file in spreadsheet software. 5. The spreadsheet interprets the attacker-controlled value as a formula. 6. Depending on the spreadsheet product and its se ...[truncated 716 chars]- Remediation
View remediation
[ lead.business, lead.permitType, lead.address, lead.city, lead.email || '', lead.status, lead.date ].map(csvCell).join(',')).join('\n'); fs.writeFileSync(filename, header + rows); } ``` ]]>
