xlsx
npm5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting xlsxpage 1 of 1
- CVE-2021-32012MEDIUMCVSS 5.5EG 5.5✓ Fixed in 0.17.02021-07-19
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 1 of 2).
- CVE-2021-32013MEDIUMCVSS 5.5EG 5.5✓ Fixed in 0.17.02021-07-19
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 2 of 2).
- CVE-2021-32014MEDIUMCVSS 5.5EG 5.5✓ Fixed in 0.17.02021-07-19
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (CPU consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js.
- CVE-2023-30533HIGHCVSS 7.8EG 7.82023-04-24
SheetJS Community Edition before 0.19.3 allows Prototype Pollution via a crafted file. In other words. 0.19.2 and earlier are affected, whereas 0.19.3 and later are unaffected.
- CVE-2024-22363HIGHCVSS 7.5EG 7.52024-04-05
SheetJS Community Edition before 0.20.2 is vulnerable.to Regular Expression Denial of Service (ReDoS).
Check whether xlsx is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for xlsx CVEs against the assets you own.
Start Free Scan →