CVE-2026-34084 (matched: php)

  • Monday, 27th July, 2026
  • 22:03pm

A security flaw has been found in PhpSpreadsheet, a popular library that many websites and web applications use to work with spreadsheet files like Excel, Google Sheets, and CSV files.

Versions 1.30.2 and older, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0 of the library are affected. If your site or app uses one of these versions and lets users control the filename used to load a spreadsheet file, an attacker could exploit this issue to run unauthorized commands on your web server (if the application has the required supporting code in place), or trick your server into sending requests to other systems without your permission. This happens because the library fails to properly validate special file path formats that point to remote or specially formatted file sources instead of normal uploaded spreadsheets.

The vulnerability has been patched in newer versions of PhpSpreadsheet: 1.30.3, 2.1.15, 2.4.4, 3.10.4, and 5.6.0.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-34084

« Back