PT-2026-107659 · Excelize · Excelize

CVE-2026-107221

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Excelize versions 2.0.0 through 2.11.0
Description An issue exists in the checkRow function where the size of the target cell slice is determined by the last cell in the XML document order. If a crafted spreadsheet contains a row where a cell appearing earlier in the document references a higher column than the final cell, the column index exceeds the slice length. This occurs when a non-streaming worksheet API, such as GetCellValue(), GetCellFormula(), CalcCellValue(), GetMergeCells(), or SetCellValue(), is used to read the sheet. An attacker can exploit this by providing a specially crafted file to cause an unrecovered panic, leading to a process crash.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107221
GHSA-8MCQ-6WMR-JRJV

Affected Products

Excelize