CVE-2026-78207Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

exceljs through 4.4.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with a malicious __proto__ property to cell notes, modifying Object.prototype and affecting all plain objects created in the process.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-24: 2Patch / Workaround · 2026-08-24: 1Technical Details · 2026-08-24: 208-24
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - exceljs / exceljs-hardened Prototype Pollution via cell note deepMerge (CVE-2026-78207) exceljs and its exceljs-hardened fork share a deepMerge helper that merges cell note objects without blocking proto/constructor/prototype keys. An attacker can feed parsed JSON with a malicious proto in cell notes to poison Object.prototype during workbook processing, impacting other plain objects and potentially leading to logic/RCE chains. 👉Affected: exceljs <= 4.4.0 (no fix available), exceljs-hardened < 5.0.0 | Upgrade exceljs-hardened to 5.0.0

    Post summary

    The post announces CVE-2026-78207, a prototype‑pollution vulnerability in exceljs/ exceljs-hardened, providing technical details and a recommended upgrade, but no PoC, exploit code, or evidence of active exploitation.

    0000086
    294 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-78207 Prototype Pollution in exceljs-hardened Before 5.0.0 in deepMerge Helper https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-78207

    Post summary

    A prototype‑pollution vulnerability (CVE-2026-78207) in exceljs‑hardened prior to v5.0.0 has been disclosed, but no PoC, exploit, or patch details are provided.

    00000135
    4.1K followersView on X

Explore more