Skip to content

[data grid] CVE-2026-41907 uuid package in @mui/x-internal-exceljs-fork #22267

Description

@jst-schraml

Hey there.

We are tracking CVEs for our projects and data grid premium is causing warnings because of GHSA-w5hq-g745-h8pq.
The @mui/x-data-grid-premium@8 package depends on @mui/x-internal-exceljs-fork@4 which depends on uuid@8.
Now the CVE specifically states that uuid v4 is not affected and from this exceljs issue text i would assume that your internal fork also only uses uuid v4.
So this CVE is probably not that relevant to you. Would just like to get rid of the CVE in our tracker.
Would it be possible for you to upgrade your uuid dependency to package version 14?

Thanks

Metadata

Metadata

Assignees

No one assigned

    Labels

    plan: PremiumImpact at least one Premium user.scope: data gridChanges related to the data grid.securityPull requests that address a security vulnerability.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions