CVE-2026-78207
exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, construct
CVSS
9.4
Crítico
EPSS
0.4%
p37
KEV
—
Exploit Today
11
0-100
Publicado: 24 ago 2026 · Última mod.: 24 ago 2026 · CWE-1321
0.4%EPSS · 30 días0.4%
2026-08-242026-08-27
exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with a malicious __proto__ property to cell notes, modifying Object.prototype and affecting all plain objects created in the process.
- github.comhttps://github.com/exceljs/exceljs
- github.comhttps://github.com/exceljs/exceljs/blob/v4.4.0/lib/utils/under-dash.js#L155-L181
- github.comhttps://github.com/mateocallec/exceljs-hardened/security/advisories/GHSA-qwr4-7h29-chpf
- www.vulncheck.comhttps://www.vulncheck.com/advisories/exceljs-through-prototype-pollution-via-deepmerge-reached-from-note-serialization
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-822574.3 MED—
———SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arbitrary user-controlled path names. Attackers can manipulate the deletion path to remove methods on the prototype, potentially disabling application functionality.12hCVE-2026-781817.3 ALT36.5%
——11A weakness has been identified in ractivejs ractive up to 1.4.4. Impacted is the function Ractive#set of the component Keypath Handler. Executing a manipulation can lead to improperly controlled modification of object prototype attributes. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.3dCVE-2026-781807.3 ALT36.5%
——11A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider.getContextProps of the file components/dialog/index.tsx of the component deepMerge. Performing a manipulation of the argument locale results in improperly controlled modification of object prototype attributes. The attack may be initiated remotely. The reported GitHub issue was closed automatically due to inactivity.5dCVE-2026-781796.3 MED25.4%
——8A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability affects the function SetValue of the file plugins/utils/object/SetValue.js of the component BehaviorTree Blackboard Data Interface. Such manipulation of the argument key leads to improperly controlled modification of object prototype attributes. The attack can be launched remotely.5dCVE-2026-781787.3 ALT36.5%
——11A vulnerability was determined in jQWidgets up to 24.0.1. This affects the function JQXLite.extend/jqxBaseFramework.extend of the file jqwidgets/jqx-all.js. This manipulation causes improperly controlled modification of object prototype attributes. The attack can be initiated remotely. The reported GitHub issue was closed with the label "not planned".2dCVE-2026-184208.8 ALT49.1%
——15Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code execution.
To remediate this issue, users should upgrade to OpenSearch Dashboards 3.8 or later.3d