Executive brief
The exceljs library, used for reading and writing Excel files in Node.js applications, is vulnerable to a security flaw that allows malicious code to be embedded in spreadsheet cells. If an application uses this library to display spreadsheet data in a web browser, an attacker could execute unauthorized scripts in the user's session. This could lead to the theft of sensitive information, such as login tokens, or unauthorized actions performed on behalf of the user.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in exceljs versions prior to 1.6.0. The library fails to properly sanitize or escape data parsed from XLSX files before it is embedded into HTML tags within sheet cells. An attacker can craft a malicious XLSX file containing script tags (e.g., <script>alert(1)</script>) in cell values. When a web application uses the library to render this spreadsheet data in a browser, the injected scripts execute in the context of the user's session. This is classified as CWE-79 and requires the victim to view the malicious spreadsheet data. The issue is resolved in version 1.6.0.
Affected products
- exceljs project exceljs < 1.6.0
Timeline
- 2018-05-24: other: Vulnerability reported via HackerOne
- 2018-09-06: disclosed: NVD publication date
- 2018-09-11: advisory: GitHub Advisory published
- 2018-09-11: patched: Version 1.6.0 released