HIGHVulnerability

CVE-2026-78209

exceljs through 4.4.0 fails to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported cell values can inject formulas that execute when the CSV file is opened in a spreadsheet application, potentially exfiltrating data or performing other malicious actions.

Properties

severity
HIGH
score
8.2
cve_id
CVE-2026-78209
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
published_at
2026-08-24T01:16:58.423
last_modified
2026-08-31T20:52:56.343

Related Entities (2)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Formula Elements in a CSV File

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-78209 — Ninja Signal Threat Intelligence | Ninja Signal