PT-2026-47606 · Phpoffice+2 · Phpspreadsheet+1

·

CVE-2026-45034

·

Published

2026-06-08

·

Updated

2026-06-23

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PhpSpreadsheet versions prior to 1.30.5
Description An issue exists in the File::prohibitWrappers() function where the use of parse url() to detect stream wrappers can be bypassed. When an input contains three or more slashes after the scheme (e.g., phar:///path/file.phar/inner), parse url() returns a boolean false instead of the scheme string, allowing the check to be skipped. This enables the IOFactory::load() function to process phar wrappers.
On PHP 7.x, this can lead to remote code execution (RCE) because the system automatically deserializes phar metadata via is file, triggering the wakeup() and destruct() magic methods of attacker-controlled objects. On PHP 8.x, the impact is reduced to a phar wrapper file read primitive, as automatic metadata deserialization was removed; RCE would only occur if the downstream consumer calls Phar::getMetadata().
Recommendations Update to version 1.30.5 or newer. As a temporary workaround, restrict the use of the IOFactory::load() function with untrusted input to prevent the processing of malicious phar wrappers.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45034
GHSA-87M4-826X-3CRX

Affected Products

Phpspreadsheet
Phpoffice Phpspreadsheet