npm package for detecting suspicious uploads.
-
Updated
Oct 3, 2026 - TypeScript
npm package for detecting suspicious uploads.
CSV Injection Payload List
🥷 Prevent CSV injection and data exfiltration
File-upload validation microservice for .NET: multi-format script-injection detection (PDF, Office, CSV, images) + optional ClamAV antivirus layer.
CVE-2021-46363: Formula Injection in Magnolia CMS
A zero-config, language-agnostic gate that statically flags CSV/formula injection - code writing user-controlled data to CSV/spreadsheet output without neutralizing the formula-trigger characters (= + - @ tab CR) that let a cell execute in Excel/Sheets. Single Go binary. Grounded in OWASP CSV Injection / CWE-1236.
CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality.
Paste a model response and see every URL your renderer would silently GET, every cell a spreadsheet would run as a formula, and every terminal escape that overwrites what you read.
Write CSV files Excel can't mangle (leading zeros, long IDs, dates, gene names, CSV injection, Korean/CJK text) and read the CSVs Excel produces. Zero deps, TypeScript, Node/browser/Deno/Bun.
Secure output sanitization and input inspection for JSON/JSONL, CSV, and TSV — guards against formula injection, bidi-override, control-character, and encoding attacks.
To associate your repository with the csv-injection topic, visit your repo's landing page and select "manage topics."