CVE-2026-78207 | exceljs exceljs-hardened prior 5.0.0 deepMerge prototype pollution

SecurityVulns

A vulnerability was found in exceljs exceljs-hardened. It has been declared as critical. Affected by this issue is the function deepMerge. Executing a manipulation can lead to improperly controlled modification of object prototype attributes.

This vulnerability is tracked as CVE-2026-78207. The attack can be launched remotely. No exploit exists.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More