SheetJS Community Edition before 0.20.2 is vulnerable.to Regular Expression Denial of Service (ReDoS).
A non-vulnerable version cannot be found via npm, as the repository hosted on GitHub and the npm package xlsx are no longer maintained. Version 0.20.2 can be downloaded via https://cdn.sheetjs.com/.
{
"severity": "HIGH",
"github_reviewed": true,
"cwe_ids": [
"CWE-1333"
],
"nvd_published_at": "2024-04-05T06:15:10Z",
"github_reviewed_at": "2024-04-08T13:47:03Z"
}