defusedcsv
Drop-in replacement for Python's CSV library that tries to mitigate CSV injection attacks
Decision gist · record as of 2026-08-14
Yes, if you export CSV files containing any user-generated data. The library is lightweight, has no dependencies, and solves a real attack surface with minimal code changes. The aging maintenance status (346 days since last release) is not a blocker for a stable, narrow-scope utility, but monitor the repository for any security disclosures. No known vulnerabilities are recorded.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Low friction: pure Python wheel with no runtime dependencies.
- Maintenance is aging—last release was 346 days ago, though the repository remains active with a recent commit on 2025-09-03.
License · maintenance · safety
Apache License 2.0 (permissive) — Apache License 2.0 (permissive) places no restrictions on use or distribution; you may use this in commercial or proprietary projects without obligation to share modifications.
last release 2025-09-02 (346 days) · last repo commit 2025-09-03 · 27 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 1,473,625 downloads/mo, #3,864 on PyPI
Alternatives
Verify before relying
from defusedcsv import csv
import io
output = io.StringIO()
writer = csv.writer(output)
writer.writerow(['@formula', 'normal_data', '=SUM()'])
print(output.getvalue())- Whether the escaping strategy (prepending apostrophe, replacing pipe characters) is sufficient against all known CSV injection vectors or if newer attack patterns exist.
- Real-world compatibility with spreadsheet software versions beyond the implicit testing mentioned in the description.
- Whether the library's defense remains effective across all supported Python versions (3.9 to 3.13).
What it is and what it does
Defusedcsv wraps Python's standard csv module to defend against CSV injection attacks—a vulnerability where malicious formulas in user-generated data can execute when a spreadsheet application opens the exported file. The library intercepts cells that begin with formula-triggering characters (@, +, -, =, |, %) and prepends an apostrophe to neutralize them; it also replaces pipe characters in those cells with escaped equivalents. The apostrophe remains invisible to end users in most spreadsheet software, making the defense transparent.
It is designed as a drop-in replacement: you swap `import csv` for `from defusedcsv import csv` and use the API identically. The library supports Python 3.9 to 3.13 and carries no external dependencies, making installation and integration straightforward. The trade-off is that the resulting CSV files are slightly altered—cells that would have triggered formulas are now safe but visually different in raw form.
Use it for
- Exporting user-submitted survey or form data to CSV without risk of formula injection in recipient spreadsheets.
- Building a web application that generates downloadable CSV reports from untrusted user input.
- Protecting against accidental or deliberate CSV injection when aggregating data from multiple sources into a single export file.
- Ensuring compliance with security best practices when handling CSV export in multi-tenant SaaS platforms.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you export CSV files containing any user-generated data.
The library is lightweight, has no dependencies, and solves a real attack surface with minimal code changes. The aging maintenance status (346 days since last release) is not a blocker for a stable, narrow-scope utility, but monitor the repository for any security disclosures. No known vulnerabilities are recorded.
Install
defusedcsv on PyPI
Before you install
Low friction: pure Python wheel with no runtime dependencies. Maintenance is aging—last release was 346 days ago, though the repository remains active with a recent commit on 2025-09-03.
License in practice
Apache License 2.0 (permissive) places no restrictions on use or distribution; you may use this in commercial or proprietary projects without obligation to share modifications.
Quickstart
from defusedcsv import csv
import io
output = io.StringIO()
writer = csv.writer(output)
writer.writerow(['@formula', 'normal_data', '=SUM()'])
print(output.getvalue())
Verify before relying
- Whether the escaping strategy (prepending apostrophe, replacing pipe characters) is sufficient against all known CSV injection vectors or if newer attack patterns exist.
- Real-world compatibility with spreadsheet software versions beyond the implicit testing mentioned in the description.
- Whether the library's defense remains effective across all supported Python versions (3.9 to 3.13).
Package facts
| License | Apache License 2.0 permissive |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Aging 346 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 1,473,625 / month, #3,864 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Intended Audience :: DevelopersIntended Audience :: Other AudienceLicense :: OSI Approved :: Apache Software LicenseProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.9 |
Evidence: defusedcsv-3.0.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “csv injection prevention”
- defusedcsvDefusedcsv is a drop-in replacement for Python's standard csv module…
- MarkupSafeMarkupSafe provides a text object that escapes special characters so…
- shellescapeProvides a `quote()` function that shell-escapes Python strings to…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also unicodecsv · logging-formatter-anticrlf · MarkupSafe · csvkit · xlcalculator · xlsx2csv · clevercsv · tarsafe · tablib · pytablewriter