CVE-2026-78209 HIGH

CVE-2026-78209: exceljs through 4.4.0 CSV Formula Injection via Unescaped Cell Values

Vendor Exceljs
Product exceljs
Weakness CWE-1236
Published August 24, 2026
Last update August 29, 2026

CVSS base score

8.4/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N

What the vulnerability does

01Description

exceljs through 4.4.0 fails to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported cell values can inject formulas that execute when the CSV file is opened in a spreadsheet application, potentially exfiltrating data or performing other malicious actions.

Key dates

02Disclosure timeline

August 24, 2026 CVE published
August 29, 2026 Record updated