Releases108
Frequency4 weeks 7 hours
Last Release
SheetJS Spreadsheet data parser and writer

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
all versions7.5 HIGH

SheetJS Community Edition before 0.20.2 is vulnerable.to Regular Expression Denial of Service (ReDoS).

all versions7.8 HIGH

SheetJS Community Edition before 0.19.3 allows Prototype Pollution via a crafted file. In other words. 0.19.2 and earlier are affected, whereas 0.19.3 and later are unaffected.

< 0.17.05.5 MEDIUM4.3 MEDIUM

SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 1 of 2).

< 0.17.05.5 MEDIUM4.3 MEDIUM

SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 2 of 2).

< 0.17.05.5 MEDIUM4.3 MEDIUM

SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (CPU consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js.