THREAT OPS › Threat News › [NVD] CVE-2026-78209 (HIGH 8.2) — exceljs through 4.4.0 fails to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported cell values can inject formulas that execute when the CSV file is opened in a spreadsheet application, potentially exfiltr
[NVD] CVE-2026-78209 (HIGH 8.2) — exceljs through 4.4.0 fails to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported cell values can inject formulas that execute when the CSV file is opened in a spreadsheet application, potentially exfiltr
CVE-2026-78209 CVSS: 8.2 HIGH Published: 2026-08-24T01:16:58.423
exceljs through 4.4.0 fails to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported cell values can inject formulas that execute when the CSV file is opened in a spreadsheet application, potentially exfiltrating data or performing other malicious actions.
Indicators of compromise
- CVE-2026-78209cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-78209