T09 · Insecure Skill Coding Practices
- Location
scripts/pdf_to_excel.py:34- Finding
Spreadsheet Formula Injection in Generated Excel Workbooks
- Content
View full analysis
1 else [] df = pd.DataFrame(data, columns=headers) df.to_excel(writer, sheet_name=sheet_name[:31], index=False) ``` From `scripts/extract_tables.py`: ```python with pd.ExcelWriter(output_path, engine='openpyxl') as writer: for idx, table_info in enumerate(tables_data): sheet_name = f"Page{table_info['page']}_Table{table_info['table_index']}" df = pd.DataFrame(table_info['data'][1:], columns=table_info['data'][0]) df.to_excel(writer, sheet_name=sheet_name[:31], index=False) ``` ### Technical Analysis The scripts treat PDF text, table headers, and table cells as trusted data and write them directly to XLSX workbooks through Pandas and OpenPyXL. An attacker can construct a PDF whose extracted cell content begins with a formula marker, particularly `=`. Such values may be stored as spreadsheet formulas rather than inert text. The vulnerability affects both table content and, depending on serialization behavior, column headers derived from the PDF. No validation or neutralization occurs before workbook generation. Formula behavior depends on the spreadsheet application and its security configuration. Potential payloads include external workbook references, network-triggering formulas, deceptive hyperlinks, and application-specific formula mechanisms capable of exposing data. ### Attack Path 1. An attacker creates a PDF containing a table cell such as an external-reference or hyperlink formula beginning wit ...[truncated 1105 chars]- Remediation
View remediation
