在 exceljs-hardened 5.0.0 之前的版本中,Workbook.addImage() 函数存在一个路径穿越漏洞,该函数未对文件路径进行验证。攻击者可以提供任意文件路径,读取 Node.js 进程可以访问的任何文件,并将其嵌入生成的工作簿中。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-78207 | 9.4 CRITICAL | exceljs through 4.4.0 Prototype Pollution via deepMerge Reached From Note Serialization |
| CVE-2026-78209 | 8.2 HIGH | exceljs through 4.4.0 CSV Formula Injection via Unescaped Cell Values |
| CVE-2026-78206 | 7.5 HIGH | exceljs through 4.4.0 Uncontrolled Resource Consumption via Unbounded xlsx Decompression |
No comments yet