SheetJS develops a JavaScript spreadsheet-parsing and generation library widely embedded in web applications and data-processing pipelines, with vulnerabilities centering on its core product and derived commercial variant. The observed weakness classes—prototype pollution and uncontrolled resource consumption—reflect the parsing and object-manipulation risks inherent to a dynamic-language library handling untrusted spreadsheet input, and are characteristic attack surfaces for this class of utility library. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sheetjs over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-30533HIGH SheetJS Community Edition before 0.19.3 allows Prototype Pollution via a crafted file. In other words. 0.19.2 and earlier are affected, whereas 0.19.3 and later are unaffected. | Apr 24, 2023 | 7.8 | 20 | NO | NO |
CVE-2021-32014MEDIUM SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (CPU consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js. | Jul 19, 2021 | 5.5 | 20 | NO | NO |
CVE-2021-32013MEDIUM SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issu | Jul 19, 2021 | 5.5 | 20 | NO | NO |
CVE-2021-32012MEDIUM SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issu | Jul 19, 2021 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sheetjs.
Media articles that mention a CVE ID that affects a product developed by Sheetjs — matched by CVE ID, not by vendor name.