top of page
perceptive_background_267k.jpg

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.…

Published:

28 juli 2026 om 00:00:00

Alert date:

28 juli 2026 om 22:07:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Supply Chain & Dependencies, Data Breach & Exfiltration, Cloud & Virtualization

CVE-2026-59931 affects PhpSpreadsheet, a pure PHP library for reading and writing spreadsheet files. Multiple version ranges are vulnerable, including 4.0.0–5.8.0, 3.3.0–3.10.6, 2.2.0–2.4.6, 2.0.0–2.1.17, and all releases up to 1.30.5. The vulnerability exists in the WEBSERVICE() function, where the domain whitelist validation in Calculation/Web/Service.php can be bypassed because PHP's HTTP stream wrapper automatically follows 301/302 redirects without re-validating the redirect target. An attacker can upload a crafted XLSX file to trigger a redirect from a whitelisted domain to an arbitrary internal URL, achieving a full-read SSRF. This can be exploited to exfiltrate cloud metadata credentials (AWS/GCP/Azure via 169.254.169.254), access internal services, and perform internal port scanning. Up to 32,767 bytes of the response body can be returned as a cell's calculated value. Patches are available in versions 5.8.1, 3.10.7, 2.4.7, 2.1.18, and 1.30.6.

Technical details

Mitigation steps:

Affected products:

PhpSpreadsheet 4.0.0–5.8.0
PhpSpreadsheet 3.3.0–3.10.6
PhpSpreadsheet 2.2.0–2.4.6
PhpSpreadsheet 2.0.0–2.1.17
PhpSpreadsheet <=1.30.5

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page