T09 · Insecure Skill Coding Practices
- Location
scripts/csv_analyze.py:101- Finding
Spreadsheet Formula Injection in Exported CSV Files
- Content
View full analysis
1000" --output result.csv ``` 3. The malicious row satisfies the filter condition. 4. `writerows(filtered)` copies the malicious cell unchanged into `result.csv`. 5. The user opens `result.csv` in spreadsheet software. 6. Depending on the spreadsheet application and its security configuration, the formula may execute automatically or after a security prompt. ### Impact Assessment Exploitation occurs in the security context of the user who opens the exported CSV, rather than during execution of the Python script itself. Depending on spreadsheet capabilities and security settings, a malicious formula could: - Initiate external network requests and disclose data embedded in the spreadsheet. - Display deceptive or attacker-controlled content. - Invoke dangerous spreadsheet features or external programs where leg ...[truncated 307 chars]- Remediation
View remediation
