CVE-2026-78208

high

Description

exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attackers can supply arbitrary file paths to read any file accessible to the Node.js process and embed it in the generated workbook.

References

https://www.vulncheck.com/advisories/exceljs-through-path-traversal-via-unvalidated-addimage-filename

https://github.com/mateocallec/exceljs-hardened/security/advisories/GHSA-m8mg-8574-gm3m

https://github.com/exceljs/exceljs/blob/v4.4.0/lib/xlsx/xlsx.js#L421-L429

https://github.com/exceljs/exceljs/blob/v4.4.0/lib/doc/workbook.js#L142-L147

https://github.com/exceljs/exceljs

Details

Source: Mitre, NVD

Published: 2026-08-24

Updated: 2026-08-24

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: High

CVSS v4

Base Score: 8.7

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Severity: High