A security flaw has been found in PhpSpreadsheet, a common tool used by web applications to read and write spreadsheet files. This issue only impacts websites that use PhpSpreadsheet to load spreadsheet files, where the file name input for that process can be supplied or controlled by a visitor to your site. If exploited, an attacker could use this flaw to run unauthorized code on the server hosting your website, if the specific supporting components required for this exploit are present in your application. The flaw can also be used to force your server to send requests to unintended internal or external systems, which could expose sensitive data or allow access to restricted parts of your internal network. The vulnerability affects PhpSpreadsheet versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0. Fixed versions that resolve this issue are 1.30.3, 2.1.15, 2.4.4, 3.10.4, and 5.6.0.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-34084