« Back to list

Exceljs

Exceljs: vulnerabilities and CVEs

Exceljs has 4 published vulnerabilities, 4 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs4
Last 12 months4
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-78209High (8.4)0.41%—Aug 24, 2026
exceljs through 4.4.0 fails to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported cell values can inject formulas that execute when the CSV…
CVE-2026-78208High (8.7)0.51%—Aug 24, 2026
exceljs through 4.4.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attackers can supply arbitrary file paths to read any file accessible to the Node.js…
CVE-2026-78207Critical (9.3)0.60%—Aug 24, 2026
exceljs through 4.4.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with…
CVE-2026-78206High (8.7)0.63%—Aug 24, 2026
exceljs through 4.4.0 decompresses all entries from supplied xlsx archives into memory without limits on entry size, total size, or compression ratio. Attackers can upload highly compressed workbooks that expand to…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application3
  2. T1005 Data from Local System1
  3. T1059 Command and Scripting Interpreter1
  4. T1203 Exploitation for Client Execution1
  5. T1499.001 OS Exhaustion Flood1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.