CVE-2026-34084
Last modified
CVE-2026-34084 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0, when the filename argument to IOFactory::load() is user-controlled, an attacker can supply a PHP stream wrapper path (such as phar://, ftp://, or ssh2.sftp://) that passes the is_file() check in File::assertFile(). EPSS estimates a 0.71% chance of exploitation in the next 30 days.
Description
PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0, when the filename argument to IOFactory::load() is user-controlled, an attacker can supply a PHP stream wrapper path (such as phar://, ftp://, or ssh2.sftp://) that passes the is_file() check in File::assertFile(). The phar:// wrapper triggers deserialization of the PHAR metadata, which can lead to remote code execution if a suitable gadget chain is available in the application. The ftp:// and ssh2.sftp:// wrappers can be used for server-side request forgery. This issue has been fixed in versions 1.30.3, 2.1.15, 2.4.4, 3.10.4, and 5.6.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Phpoffice | Phpspreadsheet | < 1.30.3 |
| Phpoffice | Phpspreadsheet | >= 2.0.0, < 2.1.15 |
| Phpoffice | Phpspreadsheet | >= 2.2.0, < 2.4.4 |
| Phpoffice | Phpspreadsheet | >= 3.3.0, < 3.10.4 |
| Phpoffice | Phpspreadsheet | >= 4.0.0, < 5.6.0 |
References
- https://github.com/PHPOffice/PhpSpreadsheet/security/advisories/GHSA-q4q6-r8wh-5cghExploit, Mitigation, Vendor Advisory
- https://github.com/PHPOffice/PhpSpreadsheet/security/advisories/GHSA-q4q6-r8wh-5cghExploit, Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-34084?
How severe is CVE-2026-34084?
How do I fix CVE-2026-34084?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-34078Flatpak is a Linux application sandboxing and distribution f…10
- CVE-2026-34079Flatpak is a Linux application sandboxing and distribution f…7.5
- CVE-2026-3408A vulnerability was identified in Open Babel up to 3.1.1. Th…6.5
- CVE-2026-34080xdg-dbus-proxy is a filtering proxy for D-Bus connections. P…5.5
- CVE-2026-34082Dify is an open-source LLM app development platform. Prior t…4.3
- CVE-2026-34083Signal K Server is a server application that runs on a centr…6.1
- CVE-2026-34085fontconfig before 2.17.1 has an off-by-one error in allocati…7.8
- CVE-2026-34086Vulnerability in Wikimedia Foundation AbuseFilter. This iss…2.1
- CVE-2026-34087Exposure of Sensitive Information to an Unauthorized Actor v…7.5
- CVE-2026-34088Exposure of Sensitive Information to an Unauthorized Actor v…7.5
- CVE-2026-34089Vulnerability in Wikimedia Foundation Scribunto. This issue…7.5
- CVE-2026-3409A security flaw has been discovered in eosphoros-ai db-gpt 0…7.3
Are you affected by CVE-2026-34084?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
