[CVE-2026-78207] exceljs-hardened before 5.0.0 contains a prototype pollution

CVE-2026-78207 | CVSS: 9.4 | 严重级别: CRITICAL

exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with a malicious __proto__ property to cell notes, modifying Object.prototype and affecting all plain objects created in the process.

参考链接:
https://github.com/exceljs/exceljs
https://github.com/exceljs/exceljs/blob/v4.4.0/lib/utils/under-dash.js#L155-L181
https://github.com/mateocallec/exceljs-hardened/security/advisories/GHSA-qwr4-7h

📌 数据来源: NVD 官方

⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。
滚动至顶部