All versions of package x-data-spreadsheet are vulnerable to Cross-site Scripting (XSS) due to missing sanitization of values inserted into the cells.
https://github.com/advisories/GHSA-x5cw-843f-r366
https://security.snyk.io/vuln/SNYK-JS-XDATASPREADSHEET-2430381