在 exceljs-hardened 5.0.0 版本之前,该库会将提供的 XLSX 归档文件中的所有条目解压到内存中,且对单个条目大小、总大小或压缩比没有任何限制。攻击者可以上传高度压缩的工作簿,这些工作簿在内存中膨胀至 GB 级别,从而耗尽可用资源并导致拒绝服务(DoS)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-78207 | 9.4 CRITICAL | exceljs through 4.4.0 Prototype Pollution via deepMerge Reached From Note Serialization |
| CVE-2026-78209 | 8.2 HIGH | exceljs through 4.4.0 CSV Formula Injection via Unescaped Cell Values |
| CVE-2026-78208 | 7.5 HIGH | exceljs through 4.4.0 Path Traversal via Unvalidated addImage filename |
No comments yet