云虫漏洞库

CVE-2026-78209 - exceljs through 4.4.0 fails to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported cell values can inject formulas that execute when the CSV file is opened in a spreadsheet application, potentially exfiltrating data or performing other malicious actions. - 漏洞详情

漏洞编号:CVE-2026-78209

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-78209

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-1236

发布/更新时间:2026-08-24 / 2026-08-29

漏洞描述

exceljs through 4.4.0 fails to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported cell values can inject formulas that execute when the CSV file is opened in a spreadsheet application, potentially exfiltrating data or performing other malicious actions.

相关链接

相关漏洞

« 返回首页