Executive brief
exceljs is a popular Node.js library for reading and writing Excel files. A prototype pollution vulnerability in its deepMerge helper allows attackers to inject malicious code by crafting specially-formed cell note objects, potentially compromising all objects created within the application and leading to remote code execution or data manipulation.
Technical details
exceljs through version 4.4.0 contains a prototype pollution vulnerability in the deepMerge helper function, which fails to sanitize __proto__, constructor, or prototype keys when merging note objects. An attacker can supply parsed JSON with a malicious __proto__ property assigned to cell notes, which modifies Object.prototype and affects all plain objects subsequently created in the process. The vulnerability is reachable via any code that parses untrusted Excel files or JSON input and applies merging operations on note fields. This can lead to arbitrary property injection in the prototype chain, enabling remote code execution or application-level denial of service depending on how the affected properties are used downstream.
Affected products
- exceljs exceljs through 4.4.0
Timeline
- 2026-08-24: disclosed