Check CSV formulas before sharing
Separate text from formulas during import, preserve the original and inspect the delivered file rather than its preview alone.
Follow the method ↓
The answer in 30 seconds
A CSV contains text, but spreadsheet software can interpret some cells as formulas. Exports containing third-party input deserve particular attention. Encoding and delimiter checks alone do not cover this interpretation.
Keep the original, explicitly import affected fields as text and inspect cell beginnings in each column. OWASP explains that no CSV neutralisation works universally for all spreadsheet applications and downstream uses.
Examples to adapt
A response should remain text. Have untrusted fields reviewed before distributing the export.
Preserve their numerical meaning in designated columns; treat free-text comments separately.
Follow the method
- 1Identify field origins
Locate comments, names and descriptions originating in external input. Preserve the raw CSV and work on a copy.
- 2Prepare import
Calc documentation distinguishes Text column type and Evaluate formulas. Choose suitable options before loading. Excel’s Text/CSV import supports column control.
- 3Inspect content
A cell beginning with = can be interpreted as a formula. OWASP identifies other initiating characters depending on the application. Do not blindly remove legitimate negative values.
- 4Check the final copy
Compare row counts, identifiers and content with the original. Check the delivery file’s behaviour in the intended environment; do not assume escaping survives saving and reopening.
A checklist to keep
Use these checks to record your observations. They are a reading aid, not an automatic assessment.
| Check | What to examine | Action |
|---|---|---|
| Origin | Third-party input fields | Identify |
| Type | Expected text or number | Define per column |
| Import | Formula and text settings | Check |
| Fidelity | Rows, identifiers and values | Compare against original |
| Delivery | Intended software and use | Document limits |
Free, no sign-up. UTF-8 text with semicolon-separated columns.
What to check
Quoting a cell does not guarantee text interpretation in every application.
A spreadsheet-oriented protection can alter data read by a program.
Import settings and receiving software are part of the context to retain.
Common questions
Should I remove every minus sign?
No. That would alter valid values. Define each column’s intended type and handle untrusted fields separately.
Must I test a dangerous formula?
No. Document import settings and use a harmless example in an authorised test environment.
Sources and documentation
Documentation consulted on . Examples are illustrative; interfaces and results may change.
Reference record for this resource
Identify the publisher, official destination and practical checks before using the service.
Read the OWASP record →