<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Data Export on Nalar</title>
    <link>https://nalar.dev/tags/data-export/</link>
    <description>Recent content in Data Export on Nalar</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 09 Sep 2026 00:00:00 +0700</lastBuildDate>
    <atom:link href="https://nalar.dev/tags/data-export/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Treat Spreadsheet Exports as Active Content</title>
      <link>https://nalar.dev/treat-spreadsheet-exports-as-active-content/</link>
      <pubDate>Wed, 09 Sep 2026 00:00:00 +0700</pubDate>
      <guid>https://nalar.dev/treat-spreadsheet-exports-as-active-content/</guid>
      <description>&lt;p&gt;A CSV export can look harmless because the application is only writing text. The risk appears later, when a spreadsheet program opens that text and decides that a cell is a formula rather than ordinary data.&lt;/p&gt;&#xA;&lt;p&gt;If an attacker can control a field that appears in an export, a value intended to be a name, note, ticket title, or other text may be interpreted by the spreadsheet application as active spreadsheet content. The consequence depends on the spreadsheet software and its configuration, but it can include misleading calculated values, unexpected links or external interactions, and other behavior the exporting application never intended to authorize.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
