The Spreadsheet That Ran Code — JavaScript Bug Hunt

Inspired by CSV-injection advisories against every export button on the internet: a user names themselves =HYPERLINK(...) and whoever opens the exported…

  • Language: JavaScript
  • Layer: Backend
  • Difficulty: Easy
  • Concepts: Injection, CSV
  • Modelled on: CSV injection
  • Visible tests: formula starters are neutralised; plain values pass through; commas and quotes are escaped
  • Reward: 50 XP for a complete fix

Briefing

Inspired by CSV-injection advisories against every export button on the internet: a user names themselves =HYPERLINK(...) and whoever opens the exported spreadsheet executes it. Cells starting with =, +, - or @ must be neutralised with a leading apostrophe.

csvExport.js writes cells raw.

Bug report

BUG-CSV-INJ · Priority: High · Reported by: security

csvCell(value):

  • if the value starts with =, +, - or @, prefix a single quote (')
  • double every embedded double-quote and wrap in double-quotes if the value contains a comma, quote or newline

Observed: exported member lists execute formulas in Excel.

Logs

[export] cell: =HYPERLINK("http://evil","click") -> executed on open

The code as shipped

src/export/csvExport.js (editable)

// Renders one CSV cell.
exports.csvCell = function (value) {
  return value;
};

Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.