HIGH7.5
GHSA-5pgg-2g8v-p4x9
SheetJS Regular Expression Denial of Service (ReDoS)
Details
SheetJS Community Edition before 0.20.2 is vulnerable.to Regular Expression Denial of Service (ReDoS).
A non-vulnerable version cannot be found via npm, as the repository hosted on GitHub and the npm package `xlsx` are no longer maintained. Version 0.20.2 can be downloaded via https://cdn.sheetjs.com/.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/xlsx
Introduced in:
0No fixed version published yet for xlsx (npm). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-22363[ADVISORY]
- https://cdn.sheetjs.com[WEB]
- https://cdn.sheetjs.com/advisories/CVE-2024-22363[WEB]
- https://cwe.mitre.org/data/definitions/1333.html[WEB]
- https://git.sheetjs.com/sheetjs/sheetjs[PACKAGE]
- https://git.sheetjs.com/sheetjs/sheetjs/src/tag/v0.20.2[WEB]