exceljs-hardened before 5.0.0 decompresses all entries from supplied xlsx archives into memory without limits on entry size, total size, or compression ratio. Attackers can upload highly compressed workbooks that expand to gigabytes in memory, exhausting available resources and causing denial of service.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-78206 is a zip bomb vulnerability in exceljs-hardened versions before 5.0.0 that allows attackers to craft malicious XLSX files with extreme compression ratios. When processed, these archives decompress into gigabytes of data in memory without any size validation or limits, exhausting system resources and causing denial of service. This affects any application using the vulnerable library to parse user-supplied Excel workbooks, including web applications, data processing pipelines, and document management systems. The attack requires only the ability to upload or supply a specially crafted file, making it accessible to unauthenticated attackers in many scenarios.
While this CVE maps to CWE-409 (Improper Handling of Highly Compressed Data) rather than specific MITRE ATT&CK techniques, Casky's platform would help practitioners detect the attack patterns through resource exhaustion monitoring and input validation analysis. Claude's extended reasoning capabilities can correlate suspicious patterns—such as unusually small file uploads followed by massive memory allocation spikes, or processing timeouts on specific document types—with known zip bomb characteristics. Practitioners using Casky would see findings related to resource consumption anomalies (T1499: Endpoint Denial of Service) and improper input handling, alongside recommendations to implement decompression limits, file size restrictions, and sandboxed processing. Although zero matching skills exist in the current 754-skill mapping, the vulnerability underscores the need for input validation and resource control strategies that apply across multiple ATT&CK categories.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-78206. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation