AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
High 70 Monero

TransactionHistory: prevent CSV formula injection in writeCSV

Public commit record

What the developer wrote

Authored by Thomas

73/100 · Adequate
TransactionHistory: prevent CSV formula injection in writeCSV

writeCSV wrote the transaction note and subaddress label into the CSV
stripping only the quote character. A cell beginning with =, +, - or @
can be interpreted as a formula by spreadsheet software on open, which
CSV quoting does not prevent.

The transaction note can be attacker-controlled: a payment request's
tx_description is stored as the note when the payment is sent, so a
crafted note can run a spreadsheet formula when the user later exports
and opens their history, potentially enabling data exfiltration or
command execution.

Prefix affected fields with a single quote so they are treated as text;
fields beginning with whitespace or a control character are prefixed too.

Co-authored-by: selsta <selsta@sent.at>
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
The short version

What changed, and why it matters

This update fixes a security flaw in the Monero GUI wallet's export feature. When users exported their transaction history to a CSV file, the wallet stripped quote marks from transaction notes and address labels but did nothing else. If an attacker tricked a user into sending a payment with a specially crafted note beginning with =, +, -, or @, that note could become a spreadsheet formula. When the victim later exported and opened the CSV in Excel or similar software, the formula could run, potentially stealing data or running commands. The fix prefixes risky fields with a single quote so spreadsheets treat them as plain text.

Recommended action

Apply the patch and ensure any downstream CSV export logic in the Monero GUI uses the same sanitization. Users who have exported CSVs from prior versions should open them only after reviewing cells for formula payloads, or import them with data-only options. Consider adding automated tests for CSV export sanitization.

Security signals we found

01

CSV formula injection (DDE/formula payload) in exported transaction history

02

Attacker-controlled input stored as transaction note from payment request tx_description

03

Spreadsheet formula metacharacters =, +, -, @ not neutralized by prior quote-stripping

04

Patch adds input sanitization helper specifically for CSV export fields

05

Commit message explicitly describes security relevance and attack scenario

Risk score

Why this scored 70/100

Our methodology →
Potential impact 18/30
Exploitability 16/25
Stealth signal 12/15
Affected reach 10/15
Confidence 9/10
Evidence quality 5/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.