Skip to main content
https://img.shields.io/pypi/v/defusedcsv.svg https://travis-ci.org/raphaelm/defusedcsv.svg?branch=master https://codecov.io/gh/raphaelm/defusedcsv/branch/master/graph/badge.svg

If your Python application offers CSV export of user-generated data, that user-generated data might contain malicious payloads that might trigger vulnerabilities in the spreadsheet software of the user that downloads the file (i.e. MS Excel or LibreOffice).

This library tries to mitigate that by prepending all cells starting with @, +, -, =, | or % with an apostrophe ' and additionally replacing all | characters in these cells with \|. This will of course change the resulting CSV files, but Excel will not display the ' character to the user.

Tested with Python 3.9 to 3.13.

Usage

This library acts as a drop-in replacement for the standard library’s csv module. You can use it by just replacing import csv with from defusedcsv import csv in your code.

License

The code in this repository is published under the terms of the Apache License. See the LICENSE file for the complete license text.

This project is maintained by Raphael Michel <mail@raphaelmichel.de>. See the AUTHORS file for a list of all the awesome folks who contributed to this project.

Release files for defusedcsv 3.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for defusedcsv 3.0.0
File Size Uploaded
defusedcsv-3.0.0.tar.gz 9.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for defusedcsv 3.0.0
File Interpreter ABI Platform
defusedcsv-3.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 17.1 kB

Release files / defusedcsv-3.0.0.tar.gz

Download URL defusedcsv-3.0.0.tar.gz
Size 9.1 kB
Tags Source
SHA-256 checksum
How to use checksums
018678533bc375f3bf2f70f9721e48daf3800a88320dc325c1dac67ee09e2a45
BLAKE2b-256 checksum
How to use checksums
1d1d0c17ea5e5f8e456515e3368aa8821fbdf094ed29ac886f0b2f0f3779ab34
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.5

Release files / defusedcsv-3.0.0-py3-none-any.whl

Download URL defusedcsv-3.0.0-py3-none-any.whl
Size 8.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
5e5f2e940cefb5ac60580c8009388bfb154b7853784d34a8f0ff3a52c6130e87
BLAKE2b-256 checksum
How to use checksums
79aba2b9f4a1edc0828414fa4063fabe2f456e705e548dd530e0c8bc76d017e4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.5

Release history Release notifications | RSS feed

This release

3.0.0 This release

2 release files

2.0.0

2 release files

1.1.0

2 release files

1.0.1

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page