exceljs through 4.4.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with a malicious __proto__ property to cell notes, modifying Object.prototype and affecting all plain objects created in the process.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-24 01:16
Updated : 2026-08-31 20:52
NVD link : CVE-2026-78207
Mitre link : CVE-2026-78207
CVE.ORG link : CVE-2026-78207
JSON object : View
Products Affected
No product.
CWE
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
