PT-2026-79801 · Npm · Exceljs-Hardened

CVE-2026-78208

·

Published

2026-08-24

·

Updated

2026-08-29

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions exceljs-hardened versions prior to 5.0.0
Description A path traversal issue exists in the Workbook.addImage() function due to insufficient validation of file paths. This allows an attacker to provide arbitrary file paths to read any file accessible to the Node.js process and embed that file into the generated workbook.
Recommendations Update to version 5.0.0 or later. As a temporary workaround, restrict the use of the Workbook.addImage() function until the update is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78208
GHSA-M8MG-8574-GM3M

Affected Products

Exceljs-Hardened