PT-2023-4424 · Unknown · Sheetjs Community Edition

Stof

·

Published

2023-04-12

·

Updated

2025-10-31

·

CVE-2023-30533

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SheetJS Community Edition versions prior to 0.19.3
Description The issue is related to a Prototype Pollution vulnerability, which can be exploited by a remote attacker using a specially crafted file, potentially allowing for unauthorized actions. The SheetJS Community Edition receives over 2 million weekly downloads, and versions prior to 0.19.3 are affected. Workflows that do not read arbitrary files are unaffected.
Recommendations For versions prior to 0.19.3, consider avoiding the use of the affected functionality until a fixed version is available. As a temporary workaround, restrict the reading of arbitrary files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Prototype Pollution

Weakness Enumeration

Related Identifiers

BDU:2023-04769
CVE-2023-30533
GHSA-4R6H-8V6P-XVW6

Affected Products

Sheetjs Community Edition