SheetJS Community Edition before 0.20.2 is vulnerable.to Regular Expression Denial of Service (ReDoS).
A non-vulnerable version cannot be found via npm, as the repository hosted on GitHub and the npm package xlsx
are no longer maintained. Version 0.20.2 can be downloaded via https://cdn.sheetjs.com/.
{ "github_reviewed": true, "github_reviewed_at": "2024-04-08T13:47:03Z", "severity": "HIGH", "cwe_ids": [ "CWE-1333" ], "nvd_published_at": "2024-04-05T06:15:10Z" }