exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with a malicious __proto__ property to cell notes, modifying Object.prototype and affecting all plain objects created in the process.
We have discovered 385 live websites that are affected by CVE-2026-78207.
| Product | |
| Category | Font Scripts |
| Vulnerable Domains | 385 live websites (100% of ExcelJS install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 9 versions ( 100% of all versions) |
| 243 websites | |
| 10 websites | |
| 10 websites | |
| 9 websites | |
| 9 websites | |
| 7 websites | |
| 7 websites | |
| 6 websites | |
| 6 websites | |
| 6 websites |
| .com | 194 websites |
| .org | 51 websites |
| .net | 14 websites |
| .co | 13 websites |
| .com.br | 7 websites |
| .com.au | 5 websites |
| .es | 5 websites |
| .ru | 4 websites |
| .it | 4 websites |
| .co.uk | 3 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***.***.au | *,*** | ||
| ***.*****.co | ***,*** | ||
| ****.*********.gov | ***,*** | ||
| *************.org | ***,*** | ||
| *****.*********.net | ***,*** | ||
| ************.com | ***,*** | ||
| ******.************.de | *,***,*** | ||
| ***.********.gov | *,***,*** | ||
| **********.nl | *,***,*** | ||
| ***********.com | *,***,*** |