mirror of
https://github.com/usestrix/strix.git
synced 2026-09-14 14:19:09 +08:00
3c767cdd47
* fix(report): neutralize CSV formula injection in vulnerabilities.csv write_vulnerabilities() wrote finding titles straight into vulnerabilities.csv. The csv module escapes CSV syntax but has no notion of spreadsheet formula triggers, so a title beginning with =, +, -, @, tab or CR reached the cell intact and was evaluated when a human opened the file (CWE-1236). That input is attacker-influenced by design: Strix scans untrusted targets and the agent quotes target content verbatim into finding titles, so a scanned page can dictate a cell's literal contents. _validate_required_text only checks the title is non-blank. Add csv_safe() and apply it to every cell written. A value starting with a formula trigger is prefixed with an apostrophe, the standard mitigation: spreadsheets render the rest as literal text and hide the apostrophe. This follows the module's existing safe_fence() precedent, which already guards the markdown path against the same class of attacker-influenced content. Adds regression tests covering the six trigger characters, that the payload survives intact behind the guard, and that benign titles are untouched. * report: single-line titles, exact CSV bytes, accurate csv_safe docstring Strip control characters from finding titles at the ReportState choke point so the guard in the CSV writer is defense-in-depth rather than the only layer, and write artifacts with newline="" so the CSV's own \r\n terminators are not rewritten to \r\r\n on Windows. * report: normalize hydrated titles on resume * report: rewrite finding markdown when resume cleans its title --------- Co-authored-by: itzzdev09 <devved90@gmail.com>