Security issues with the export service

Dependabot gives two alerts regarding the exporting service:

SheetJS Regular Expression Denial of Service (ReDoS)

SheetJS Community Edition before 0.20.2 is vulnerable.to Regular Expression Denial of Service (ReDoS).

Prototype Pollution in sheetJS

All versions of SheetJS CE through 0.19.2 are vulnerable to “Prototype Pollution” when reading specially crafted files. Workflows that do not read arbitrary files (for example, exporting data to spreadsheet files) are unaffected.

A non-vulnerable version cannot be found via npm, as the repository hosted on GitHub and the npm package xlsx are no longer maintained.

The automatic update through dependabot interface is not possible because:

Dependabot can’t find a published or compatible non-vulnerable version for xlsx
The latest published and compatible version is 0.18.5.

Hello Nikolai,

I’ve forwarded this issue to our development team for further investigation and will update you as soon as I have news.