You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix: neutralize CSV formula injection in spreadsheet-bound exports (OWASP)
No CSV output in the project escaped spreadsheet formula triggers: a cell
like =cmd|' /C calc'!A0 or =HYPERLINK(...) in untrusted input executed
when an exported file was opened in Excel/Sheets/LibreOffice. The review
queue export is the sharpest edge - it exists to be opened by human
reviewers in spreadsheets and embeds values from the input data.
Fix:
- new freshdata._util.sanitize_csv_formulas: copies the frame and
prefixes ' to string cells and column labels starting with
= + - @ <tab> <cr> (OWASP trigger set); numeric cells (incl. negative
numbers) untouched; unchanged columns keep their dtype.
- export_review_queue: sanitizes csv output BY DEFAULT (spreadsheet-bound
artifact), opt-out via sanitize_formulas=False; jsonl/parquet untouched.
- fd.clean_csv: byte-exact by default, opt-in sanitize_formulas=True
applies only to the written file, never the returned frame.
- streaming CLI (stream/stream-kafka): opt-in --sanitize-formulas, also
covers the --quarantine exceptions export.
15 regression tests in tests/test_csv_formula_sanitize.py; the file
import-errors on main (sanitizer absent) and the flags did not exist.
0 commit comments