Skip to content

Notebook · 2026-09-24 · updated 2026-10-10

What is CSV formula injection?

How spreadsheet formula injection works, what CleanCSV's opt-in prefix does, and the cases it does not cover.

CSV formula injection happens when a program opens a text file and treats a cell as a formula because the text starts with a formula character. The file is still text. The spreadsheet is what executes it. A grid on a website should show that text as text, which is what CleanCSV does. The risk appears later, in Excel, LibreOffice, Google Sheets, or another importer.

Which cells are involved

The characters that vendors document as formula triggers are =, +, -, and @, sometimes after a tab or a carriage return. A benign example is the text =1+1 or @SUM(A1). Some real attacks use the same opening characters to start a formula the spreadsheet understands. You do not need a working example to decide whether a column should be neutralized. If the column is notes, names, or anything a stranger typed, treat a leading = as untrusted.

What CleanCSV changes, and only if you ask

Protection is off by default because it changes data. When you turn it on at download, each affected cell is prefixed with an apostrophe. The apostrophe is part of the saved text, so the cell no longer begins with the trigger character. The download dialog lists the cells and the reason for each one.

  • Spreadsheet-safe mode prefixes = and @, a leading tab or carriage return, and + or - when the cell is not a plain number. Phone numbers such as +44 20 7946 0991 stay as dialed. A plain negative number such as -18 stays numeric.
  • Strict mode prefixes every cell whose first non-space character is =, +, -, or @, including negative numbers and phone numbers.
  • The in-memory grid is not rewritten. Only the downloaded file changes, and the summary says how many cells moved.

What this does not promise

An apostrophe prefix is a widely used mitigation. It is not a guarantee for every spreadsheet, every import wizard, and every future version. Some applications show the apostrophe. Some ignore a different prefix. Characters that merely look like an equals sign are not detected. Quoted fields are escaped with CSV rules either way, and that quoting is not the same thing as formula protection. Review the summary, keep a copy of the original, and do not describe the file as safe for every tool.

Cleanup never rewrites a cell to "make it safe" in the background. If the checkbox is off, =1+1 is downloaded as =1+1.

Open the cleaner