IA Squad
SearchPT
php · statamic/cmsHeads-up

statamic/cms: CSV export now neutralizes spreadsheet formula characters

Form submission values are now neutralized for spreadsheet formula characters when exported to CSV, preventing formula injection.

27 Jun 2026Read 1 minSeverity: schedule it

What changed

Form submission values are now neutralized for spreadsheet formula characters when exported to CSV, preventing formula injection.

Who it affects

Users of statamic/cms versions prior to 5.73.24 and 6.20.1 who export form submissions to CSV and open them in spreadsheet applications.

What to do today

Upgrade to version 5.73.24 or 6.20.1 to apply the fix.

The trail
Collected Audited Written Published