A security vulnerability has been identified in PhpSpreadsheet, a widely used tool that helps websites read and write spreadsheet files. The flaw impacts all versions up to 1.30.2, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0.
This issue only creates a risk if your website allows visitor-provided input (such as a file name entered or uploaded by a user) to be passed directly to PhpSpreadsheet's file loading function. If an attacker exploits this flaw, they may be able to run unauthorized code on your server, or use your server to send hidden, unauthorized requests to other external or private internal systems.
The team that develops PhpSpreadsheet has released updated, fixed versions of the tool (1.30.3, 2.1.15, 2.4.4, 3.10.4, and 5.6.0) that resolve this vulnerability.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-34084