Skip to content

fix(security): CSV formula injection in evidence export + unauthenticated accept-policies action (GH-097, GH-266) - #3577

Open
dennisofficial wants to merge 4 commits into
mainfrom
dennis/p3-fix-sweep
Open

dennisofficial wants to merge 4 commits into
mainfrom
dennis/p3-fix-sweep

Conversation

@dennisofficial

@dennisofficial dennisofficial commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Fixes two P3 security findings from the internal Glass House sweep.

GH-97 — CSV formula injection in evidence-form export

toCsvRow in apps/api/src/evidence-forms/evidence-forms.service.ts quoted CSV values but did nothing about spreadsheet formula prefixes. Employee/contractor-submitted free text (complaintDetails, individualsInvolved, evidence, ...) is a bare z.string().min(1), and Excel/Sheets strip the surrounding CSV quotes before evaluating a leading =, +, -, @, tab, or CR — so quoting alone was not a mitigation. Any reviewer with evidence:read exporting the CSV could execute attacker-controlled formulas.

Fix: neutralizeFormula() prefixes any value starting with =, +, -, @, tab, or CR with a single quote before quoting, so spreadsheet apps render it as text.

GH-266 — Unauthenticated use server action accept-policies

apps/portal/src/actions/accept-policies.ts exported acceptPolicy / acceptAllPolicies, which push a caller-supplied memberId onto any policy's signedBy with no session, membership, or org checks. Repo-wide grep confirmed it is unreferenced dead code (no imports, only one comment reference), so Next.js exposes no action id today — but a single future import would flip it into a P0-shaped compliance-attestation forgery.

Fix: deleted the dead action. The live, authenticated equivalent already exists at apps/portal/src/app/api/portal/accept-policies/route.ts (session + member-belongs-to-user checks). Also updated the one stale comment in apps/app/src/trigger/tasks/task/policy-acknowledgment-digest-helpers.ts that pointed at the deleted file.

Verification

  • Regression tests added in apps/api/src/evidence-forms/evidence-forms.service.spec.ts covering =, +, -, @ neutralization, benign-value passthrough, embedded-quote escaping, and the reviewer-role gate. bunx jest src/evidence-forms → 3 suites, 30 tests passed.
  • ESLint clean on all touched files.
  • Typecheck: no errors in any touched file. apps/api (22 errors) and apps/app (15 errors) have pre-existing failures on origin/main in unrelated test files (trigger specs, cloud-tests/documents/integrations test mocks) — verified identical with these changes stashed. apps/portal has no typecheck script; the deleted file was verified unreferenced repo-wide.

Summary by cubic

Fixes two security findings from an internal sweep: CSV formula injection in evidence-form exports and an unauthenticated policy-acceptance server action.

  • Neutralizes exported CSV values starting with =, +, -, @, tab, CR, or line feed (plus the full-width variants \uFF1D, \uFF0B, \uFF0D, \uFF20) by prefixing them with a single quote so spreadsheet apps render them as text (Add policy comments functionality #97).
  • Deletes the unused accept-policies server action that pushed a caller-supplied memberId onto any policy's signedBy without auth checks; the authenticated API route already covers this flow (chore: update dependencies and improve localization handling #266).
  • Adds regression tests for prefix and full-width neutralization, benign-value passthrough, newline-smuggled formulas, embedded-quote escaping, and the reviewer-role export gate.

Written for commit 88ce8ab. Summary will update on new commits.

Review in cubic

@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@dennisofficial
dennisofficial marked this pull request as ready for review September 23, 2026 20:11

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 4 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread apps/api/src/evidence-forms/evidence-forms.service.ts Outdated
Comment thread apps/api/src/evidence-forms/evidence-forms.service.ts
@dennisofficial

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review it

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 24, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review it

@dennisofficial I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 4 files

Heads up: you’re close to your flex budget. Increase your flex budget so reviews don’t pause.

Fix all with cubic | Re-trigger cubic

Comment thread apps/api/src/evidence-forms/evidence-forms.service.ts Outdated

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants