CVE-2023-30533
HighAdvisory
Published 24 Apr 2023In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.8
- base score, highest
- EPSS
- 0.010
- 61st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 17
- of 17,781 indexed, latest versions
- Container images
- 16
- deployed by those charts
- Fix available
- None
- affected package
Prototype Pollution in sheetJS
Carried by container images the latest versions of 17 of 17,781 indexed charts deploy, on 16 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| xlsxnpm | 0.16.9, 0.17.5, 0.18.5, 0.19.3+2 more | no fix listed | 16 |
- OSV records
- GHSA-4r6h-8v6p-xvw6
Charts affected
17 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| budibasebudibase | 0.0.0-master | 1 of 7See more | 10,775 |
| n8nn8n | 0.23.0 | 1 of 1See more | 5,639 |
| baserowbaserow-chartVerified publisher | 1.0.56 | 1 of 6See more | 17,263 |
| n8none-acre-fundVerified publisher | 0.1.52 | 1 of 3See more | 7,776 |
| nocodbzekker6Verified publisher | 1.10.0 | 1 of 1See more | 4,016 |
| data-fairdata354-helmVerified publisher | 1.1.2 | 1 of 12See more | 38,346 |
| n8nn8n-helm | 2.25.7 | 1 of 1See more | 2,575 |
| nocodbinseefrlab | 0.2.0 | 1 of 1See more | 781 |
| n8njanip81-helm-chartsVerified publisher | 0.1.4 | 1 of 1See more | 5,826 |
| image-storage-servicejtektVerified publisher | 0.4.3 | 1 of 4See more | 22,589 |
| sqlpadkronkltdVerified publisher | 0.1.0 | 1 of 1See more | 3,397 |
| portfolio-trackerkubernetes-homelab-helm-chartsVerified publisher | 0.1.0 | 1 of 3See more | 1,498 |
| finance-portalmojaloop | 5.1.4 | 1 of 11See more | 14,809 |
| reporting-legacy-apimojaloop | 2.2.0 | 1 of 1See more | 1,948 |
| nocodbone-acre-fundVerified publisher | 0.4.6 | 1 of 3See more | 4,219 |
| claude-relayrevolution1 | 0.1.37 | 1 of 4See more | 4,600 |
| simple-prima-notavcnngrVerified publisher | 0.5.3 | 1 of 4See more | 4,768 |
Container images carrying it
16 by charts deploying them
A fixed version is listed for 0 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| mojaloop/ | d480a62103d6 | xlsx | no fix listed | 2 |
| baserow/ | 566d24c7d9f5 | xlsx | no fix listed | 1 |
| budibase/ | 44fe6feab985 | xlsx | no fix listed | 1 |
| n8nio/ | 761374d4eb84 | xlsx | no fix listed | 1 |
| n8nio/ | 8b39ed5a2de9 | xlsx | no fix listed | 1 |
| n8nio/ | a9195bc499a3 | xlsx | no fix listed | 1 |
| n8nio/ | dd171d45102a | xlsx | no fix listed | 1 |
| nocodb/ | 4b760f0d2547 | xlsx | no fix listed | 1 |
| nocodb/ | 6779a4ddedf2 | xlsx | no fix listed | 1 |
| nocodb/ | d9516f0bf546 | xlsx | no fix listed | 1 |
| sqlpad/ | d3d2f430dffd | xlsx | no fix listed | 1 |
| vcnngr/ | eaf44ad0ad1f | xlsx | no fix listed | 1 |
| ghcr.io/ | cc9498b64b5b | xlsx | no fix listed | 1 |
| ghcr.io/ | 56efa3085895 | xlsx | no fix listed | 1 |
| ghcr.io/ | 398c34934453 | xlsx | no fix listed | 1 |
| public.ecr.aws/ | b1493760c716 | xlsx | no fix listed | 1 |