← Terug naar overzicht

exceljs-hardened versions before 5.0.0 contain a CSV formula injection vulnerability due to failure to neutralize leading special characters (equals, plus, minus, at signs) in cell values written to CSV output. Attackers who can influence exported cell values can inject malicious formulas that execute when the CSV file is opened in a spreadsheet application such as Microsoft Excel or LibreOffice Calc. This type of attack, also known as CSV injection or formula injection, can lead to data exfiltration or other malicious actions. The vulnerability affects the CSV export functionality in the exceljs-hardened library. Users are advised to upgrade to version 5.0.0 or later to mitigate the risk. The issue is tracked as CVE-2026-78209 and has been assigned a high criticality rating.

Affected products

  • exceljs
  • exceljs-hardened

Related CVE's

  • CVE-2026-78209

Categories

  • Data Breach & Exfiltration
  • Supply Chain & Dependencies
  • Web Technologies