T09 · Insecure Skill Coding Practices
- Location
references/build-excel.md:183- Finding
Spreadsheet Formula Injection Through Untrusted Recruitment Data
- Content
View full analysis
Vulnerability Details
File Location:
references/build-excel.md:183-204
Vulnerability Type: Spreadsheet formula injection
Risk Level: HighVulnerable Code
python # Sheet 1 ws1 = wb.create_sheet("审批总览") ws1.append(SHEET1_HEADERS) for idx, r in enumerate(rows, 1): ws1.append([ idx, r.get("serial",""), r.get("status",""), r.get("submit_time",""), r.get("end_time",""), r.get("name",""), r.get("position",""), r.get("phone",""), r.get("email",""), r.get("school",""), r.get("prior_jobs",""), r.get("cv",""), r.get("node_resume_screen",""), r.get("node_r1",""), r.get("node_r2",""), r.get("node_r3",""), r.get("node_handle","") ]) _style_header(ws1, SHEET1_HEADERS, SHEET1_WIDTHS) ws1.freeze_panes = "A2" # Sheet 2 ws2 = wb.create_sheet("节点流转明细") ws2.append(SHEET2_HEADERS) for r in rows: for t in r.get("tasks", []): ws2.append([ r.get("name",""), r.get("position",""), r.get("serial",""), t.get("node_name",""), t.get("type",""), t.get("status",""), t.get("start",""), t.get("end",""), t.get("approver_oid8","") ])Technical Analysis
Values originating from Feishu approval forms and workflow tasks are written directly into workbook cells without being normalized as literal text. Spreadsheet applications interpret strings beginning with formula indicators such as
=,+,-, or@as formulas.An applicant or another party able to control a recruitment form field could place a formula in a field such as the name, position, school, employment history, or email address. The generated workbook would preserve that input as an active formula rather than harmless text.
Formula behavior varies by spreadsheet client and security configuration. Possible payloads include deceptive hyperlinks, references that expose workbook content, and formulas that cause external network requests ...[truncated 1427 chars]
- Remediation
View remediation
Remediation Suggestions
- Sanitize every externally derived value before writing it to a workbook.
- Prefix strings beginning with
=,+,-,@, tab, carriage return, or line feed with an apostrophe. - Write untrusted values using explicit text cell types rather than relying on automatic type inference.
- Apply sanitization to all sheets, including task metadata and future columns.
- Preserve the unsanitized source only in an access-controlled data store if operationally necessary; do not place it in the workbook.
- Add automated tests covering values such as
=1+1,+SUM(A1:A2),-1+2,@SUM(A1:A2), and formulas containing hyperlinks or external references. - Consider disabling external links in generated workbook metadata where supported, while recognizing that this is defense in depth rather than a replacement for input neutralization.
A suitable defensive helper is:
python def excel_safe_text(value): if value is None: return "" text = str(value) if text.startswith(("=", "+", "-", "@", "\t", "\r", "\n")): return "'" + text return textApply this helper to every value derived from forms, tasks, overrides, and other external sources before appending it to a worksheet.
