CVE-2026-78207 CRITICAL

CVE-2026-78207: exceljs through 4.4.0 Prototype Pollution via deepMerge Reached From Note Serialization

Vendor Exceljs
Product exceljs
Weakness CWE-1321
Published August 24, 2026
Last update August 29, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

exceljs through 4.4.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with a malicious __proto__ property to cell notes, modifying Object.prototype and affecting all plain objects created in the process.

Key dates

02Disclosure timeline

August 24, 2026 CVE published
August 29, 2026 Record updated