Hacker News new | past | comments | ask | show | jobs | submit login
The Underestimated Dangers of CSV Injection (georgemauer.net)
3 points by MarcellusDrum 10 months ago | hide | past | favorite | 1 comment



The article is 6 years old but the CSV Injection still works on Google Sheets and Excel. (I imported the example csv file into both platforms and the equations were executed)

Great reminder to be vigilant. Pride cometh before a fall:

> Are they a technically savvy user? Then it is even worse. They know the CSV format is just text data, there can’t possibly be anything harmful in there. Guaranteed.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: