CVE-2023-30533

HIGH

Sheetjs < 0.19.3 - Prototype Pollution

Title source: rule

Description

SheetJS Community Edition before 0.19.3 allows Prototype Pollution via a crafted file. In other words. 0.19.2 and earlier are affected, whereas 0.19.3 and later are unaffected.

Exploits (2)

nomisec WORKING POC 12 stars
by BenEdridge · poc
https://github.com/BenEdridge/CVE-2023-30533
nomisec STUB
by weareu · poc
https://github.com/weareu/xlsx

Scores

CVSS v3 7.8
EPSS 0.0770
EPSS Percentile 91.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-1321
Status published
Products (2)
npm/xlsx 0npm
sheetjs/sheetjs < 0.19.3
Published Apr 24, 2023
Tracked Since Feb 18, 2026