HIGH 8.7 NVD

CVE-2026-78208

exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attackers can suppl

exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attackers can supply arbitrary file paths to read any file accessible to the Node.js process and embed it in the generated workbook.

References

Published: 2026-08-24 · Source: NVD · Feed updated: 2026-08-24
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-08-24 via NVD.
vulnfeed aggregates 10945 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.