All versions of package x-data-spreadsheet are vulnerable to Cross-site Scripting (XSS) due to missing sanitization of values inserted into the cells.
References
https://nvd.nist.gov/vuln/detail/CVE-2022-25646
https://github.com/myliang/x-spreadsheet/…