exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with a malicious __proto__ property to cell notes, modifying Object.prototype and affecting all plain objects created in the process.
Metrics
Affected Vendors & Products
References
History
Mon, 24 Aug 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with a malicious __proto__ property to cell notes, modifying Object.prototype and affecting all plain objects created in the process. | |
| Title | exceljs through 4.4.0 Prototype Pollution via deepMerge Reached From Note Serialization | |
| First Time appeared |
Exceljs Project
Exceljs Project exceljs |
|
| Weaknesses | CWE-1321 | |
| CPEs | cpe:2.3:a:exceljs_project:exceljs:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Exceljs Project
Exceljs Project exceljs |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-24T00:30:47.125Z
Reserved: 2026-08-24T00:15:01.656Z
Link: CVE-2026-78207
No data.
Status : Received
Published: 2026-08-24T01:16:58.137
Modified: 2026-08-24T01:16:58.137
Link: CVE-2026-78207
No data.
OpenCVE Enrichment
Updated: 2026-08-24T02:30:10Z