sheet_to_html not encoding value HTML attribute correctly #2890
Labels
No Label
DBF
Dates
Defined Names
Features
Formula
HTML
Images
Infrastructure
Integration
International
ODS
Operations
Performance
PivotTables
Pro
Protection
Read Bug
SSF
SYLK
Style
Write Bug
good first issue
No Milestone
No Assignees
2 Participants
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: sheetjs/sheetjs#2890
Loading…
Reference in New Issue
No description provided.
Delete Branch "%!s(<nil>)"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
I encountered this running xlsx.mini.min.js v0.18.5.
XLSX.utils.sheet_to_html doesn't appear to HTML encode the data-v HTML attribute, so cells with quotes and/or angled brackets creates malformed HTML for me. I didn't fully verify this is the case but I was experiencing it with the one Excel file I ran into issues with.
For now, my workaround is calling this on the output of sheet_to_html (though obviously not the fix:
Thanks for reporting! This also affects the number formats.
Both parts in https://git.sheetjs.com/sheetjs/sheetjs/src/branch/master/bits/79_html.js#L84-L85 need to be escaped.