CVE-2026-78208High· 7.5▾ Twilightexceljs through 4.4.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attackers can supply arbitrary file paths to read any file accessible to the Node.js process and embed i…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 29.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
exceljs through 4.4.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attackers can supply arbitrary file paths to read any file accessible to the Node.js process and embed it in the generated workbook.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-26158High· 7.0A flaw was found in BusyBox
CVE-2026-26157High· 7.0A flaw was found in BusyBox
CVE-2025-68428High· 7.5jsPDF is a library to generate PDFs in JavaScript
CVE-2026-65125Medium· 6.6NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause external control of a file name or path
CVE-2026-61647High· 7.1NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content to local vault directories
CVE-2026-53940High· 8.8Conda is a system-level binary package and environment manager that runs on major operating systems and platforms