Skip to content

fix(csv): prevent formula injection in CSV exports (CWE-1236) - #926

Open
nikolas-sapa wants to merge 2 commits into
sharkdp:masterfrom
nikolas-sapa:fix/csv-formula-injection
Open

nikolas-sapa wants to merge 2 commits into
sharkdp:masterfrom
nikolas-sapa:fix/csv-formula-injection

Conversation

@nikolas-sapa

Copy link
Copy Markdown

Problem

When exporting benchmark results to CSV, hyperfine writes the command string and parameter values verbatim into CSV cells. Spreadsheet applications (Excel, LibreOffice Calc, Google Sheets) interpret cells beginning with =, +, -, @, tab, or carriage return as formulas, which can lead to formula injection (CWE-1236) when parameter values come from external input.

For example, --parameter-list payload '=1+1' exported to CSV contains the literal, unescaped text =1+1, which is evaluated as a live formula when the file is opened in a spreadsheet.

Fix

Add a sanitize_csv_value() helper that prefixes values beginning with formula-triggering characters with a single quote ('), forcing spreadsheet applications to display them as literal text. The helper is applied to both the command field and all parameter_* columns.

This is the standard mitigation for CWE-1236 and does not affect values that don't begin with dangerous characters. Numeric fields (mean, stddev, etc.) are unaffected since they are serialized from f64 values which cannot produce formula-interpretable strings.

Testing

Added two new tests:

  • test_csv_formula_injection_sanitization: Integration test that verifies a parameter value of =1+1 is properly escaped in the CSV output as '=1+1.
  • test_sanitize_csv_value: Unit test covering all six dangerous prefixes (=, +, -, @, \t, \r) and several safe values that should pass through unchanged.

All existing tests pass (3 unit + 39 integration).

When exporting benchmark results to CSV, hyperfine writes the command string
and parameter values verbatim. Spreadsheet applications like Excel, LibreOffice
Calc, and Google Sheets interpret cells beginning with '=', '+', '-', '@',
tab, or carriage return as formulas, which can lead to formula injection
(CWE-1236) when parameter values come from external input.

This change adds a sanitize_csv_value() helper that prefixes such values
with a single quote to force literal text interpretation, and applies it to
both the command field and all parameter_* columns.

Fixes sharkdp#915

Signed-off-by: Nikolas Sapa <84yk8btb9f@privaterelay.appleid.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant