Skip to content

1.7.1

Choose a tag to compare

@ilbee ilbee released this 27 Mar 15:13
· 15 commits to main since this release
57d9065

Security Fixes

  • HTTP Header Injection via filename (HIGH): Sanitize fileName to strip CRLF, tabs, quotes, and null bytes; apply basename() to prevent path traversal — blocks Content-Disposition header injection
  • CSV Injection in column headers (MEDIUM): Apply formula sanitization to CSV headers (not just cell values) when sanitizeFormulas is enabled — prevents spreadsheet formula injection via =, +, -, @, tab, CR, LF prefixes

Tests

  • 4 new tests covering header injection, path traversal, empty filename fallback, and formula injection in headers