The Spreadsheet That Ran Code — JavaScript Bug Hunt
Inspired by CSV-injection advisories against every export button on the internet: a user names themselves =HYPERLINK(...) and whoever opens the exported…
- Language: JavaScript
- Layer: Backend
- Difficulty: Easy
- Concepts: Injection, CSV
- Modelled on: CSV injection
- Visible tests: formula starters are neutralised; plain values pass through; commas and quotes are escaped
- Reward: 50 XP for a complete fix
Briefing
Inspired by CSV-injection advisories against every export button on the internet: a user names themselves =HYPERLINK(...) and whoever opens the exported spreadsheet executes it. Cells starting with =, +, - or @ must be neutralised with a leading apostrophe.
csvExport.js writes cells raw.
Bug report
BUG-CSV-INJ · Priority: High · Reported by: security
csvCell(value):
- if the value starts with =, +, - or @, prefix a single quote (')
- double every embedded double-quote and wrap in double-quotes if the value contains a comma, quote or newline
Observed: exported member lists execute formulas in Excel.
Logs
[export] cell: =HYPERLINK("http://evil","click") -> executed on openThe code as shipped
src/export/csvExport.js (editable)
// Renders one CSV cell.
exports.csvCell = function (value) {
return value;
};
Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.