SheetJS Community Edition before 0.19.3 allows Prototype Pollution via a crafted file. In other words. 0.19.2 and earlier are affected, whereas 0.19.3 and later are unaffected.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| xlsx(npm) | 0 | N/A | N/A |
CVSS Metrics