
🚨Critical - exceljs / exceljs-hardened Prototype Pollution via cell note deepMerge (CVE-2026-78207) exceljs and its exceljs-hardened fork share a deepMerge helper that merges cell note objects without blocking proto/constructor/prototype keys. An attacker can feed parsed JSON with a malicious proto in cell notes to poison Object.prototype during workbook processing, impacting other plain objects and potentially leading to logic/RCE chains. 👉Affected: exceljs <= 4.4.0 (no fix available), exceljs-hardened < 5.0.0 | Upgrade exceljs-hardened to 5.0.0
Post summary
The post announces CVE-2026-78207, a prototype‑pollution vulnerability in exceljs/ exceljs-hardened, providing technical details and a recommended upgrade, but no PoC, exploit code, or evidence of active exploitation.

