PT-2026-107644 · Excelize · Excelize
CVE-2026-107213
·
Published
2026-10-07
·
Updated
2026-10-08
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Excelize versions 2.9.0 through 2.11.0
Description
A nil pointer dereference occurs when the
GetSlicers() function is called on a crafted worksheet. The issue arises because the function checks for the presence of an extLst element but fails to verify if the optional ws.Drawing element exists before accessing its RID property. This allows an attacker to cause a panic, leading to the termination of an unprotected process.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Excelize