GHSA-2j2j-8rrv-264g
Dashboard / Vulnerabilities / GHSA-2j2j-8rrv-264g
Summary: Cross-Site Scripting in exceljs
Details: Versions of `exceljs` before 1.6.0 are vulnerable to cross-site scripting. This vulnerability is due to `exceljs` not validating data from parsed XLSX file and embedding HTML tags, like `<script>` directly into the sheet cells. Because of this it's possible to inject malicious JavaScript code and execute it when data from the sheet is displayed in the browser. ## Recommendation Update to version 1.6.0 or later.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-16459, https://hackerone.com/reports/356809, https://github.com/advisories/GHSA-2j2j-8rrv-264g, https://github.com/nodejs/security-wg/blob/master/vuln/npm/464.json, https://www.npmjs.com/advisories/733
Affected packages
Package
Name: exceljs
Purl: pkg:npm/exceljs
Affected ranges
Type: SEMVER
Events:
