RockteMQ-AI commented on issue #1558: URL: https://github.com/apache/rocketmq-dashboard/issues/1558#issuecomment-5248866664
**Issue Evaluation** Category: `bug` | Status: **Confirmed** The reported issue is valid. The Topic CSV export does not sanitize cell values that start with `=`, `+`, `-`, `@`, `\t`, or `\r`, enabling CSV injection attacks. **Root Cause:** Same pattern as #1560 — exported CSV data lacks sanitization for formula-prefixed values. **Severity:** Medium — CSV injection can execute arbitrary commands when the exported file is opened in spreadsheet applications. An automated fix proposal can be generated. Reply `/approve` to proceed with PR generation. --- *Automated evaluation by github-manager* -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
