You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Security Fixes
HTTP Header Injection via filename (HIGH): Sanitize fileName to strip CRLF, tabs, quotes, and null bytes; apply basename() to prevent path traversal — blocks Content-Disposition header injection
CSV Injection in column headers (MEDIUM): Apply formula sanitization to CSV headers (not just cell values) when sanitizeFormulas is enabled — prevents spreadsheet formula injection via =, +, -, @, tab, CR, LF prefixes
Tests
4 new tests covering header injection, path traversal, empty filename fallback, and formula injection in headers