PatchSiren

exceljs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH exceljs CVE published 2026-08-24

CVE-2026-78209

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-24T01:16:58.423Z and has not been modified since then. This vulnerability, CVE-2026-78209, affects exceljs through version 4.4.0, allowing attackers to inject formulas in CSV output that can execute when opened in spreadsheet applications. The vulnerability highlights the importance of secure CSV ex [truncated]

HIGH exceljs CVE published 2026-08-24

CVE-2026-78208

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-24T01:16:58.280Z and has not been modified since then. The exceljs library through version 4.4.0 contains a path traversal vulnerability in the Workbook.addImage() function. This vulnerability allows attackers to supply arbitrary file paths, potentially leading to unauthorized file access and embedd [truncated]

CRITICAL exceljs CVE published 2026-08-24

CVE-2026-78207

The exceljs library through version 4.4.0 contains a prototype pollution vulnerability in the deepMerge helper. This vulnerability allows attackers to modify Object.prototype by assigning parsed JSON with a malicious __proto__ property to cell notes, affecting all plain objects created in the process. The CVE record was published on 2026-08-24T01:16:58.137Z and has not been modified since then. The NVD en [truncated]