critical
CVE-2026-78207
exceljs-hardened prototype pollution and unbounded XLSX decompression
- Severity
- critical
- Affected product
- exceljs-hardened
- Affected versions
- exceljs-hardened < 5.0.0
- Fixed in
- exceljs-hardened 5.0.0
- Added to NewScan
- 2026-08-24
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints exceljs-hardened from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-08-24. The two advisories share the same affected range and fix, so one version-gated finding avoids duplicate upgrade advice: CVE-2026-78207 is prototype pollution in deepMerge; CVE-2026-78206 is unbounded XLSX decompression. Version-match only: mine_versions reads exact exceljs-hardened pins from anonymously served npm manifests; it does not submit a malicious workbook or merge payload.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →