


Perceptive Security
SOC/SIEM Consultancy

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.…
Published:
28 juli 2026 om 00:00:00
Alert date:
28 juli 2026 om 22:07:40
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies, Data Breach & Exfiltration, Cloud & Virtualization
CVE-2026-59931 affects PhpSpreadsheet, a pure PHP library for reading and writing spreadsheet files. Multiple version ranges are vulnerable, including 4.0.0–5.8.0, 3.3.0–3.10.6, 2.2.0–2.4.6, 2.0.0–2.1.17, and all releases up to 1.30.5. The vulnerability exists in the WEBSERVICE() function, where the domain whitelist validation in Calculation/Web/Service.php can be bypassed because PHP's HTTP stream wrapper automatically follows 301/302 redirects without re-validating the redirect target. An attacker can upload a crafted XLSX file to trigger a redirect from a whitelisted domain to an arbitrary internal URL, achieving a full-read SSRF. This can be exploited to exfiltrate cloud metadata credentials (AWS/GCP/Azure via 169.254.169.254), access internal services, and perform internal port scanning. Up to 32,767 bytes of the response body can be returned as a cell's calculated value. Patches are available in versions 5.8.1, 3.10.7, 2.4.7, 2.1.18, and 1.30.6.
Technical details
Mitigation steps:
Affected products:
PhpSpreadsheet 4.0.0–5.8.0
PhpSpreadsheet 3.3.0–3.10.6
PhpSpreadsheet 2.2.0–2.4.6
PhpSpreadsheet 2.0.0–2.1.17
PhpSpreadsheet <=1.30.5
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-59931
https://github.com/PHPOffice/PhpSpreadsheet/commit/7ef7b25e8548a6ded79dac74e2e2c7acdac38d8d
https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/1.30.6
https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/2.1.18
https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/2.4.7
https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/3.10.7
https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/5.8.1
https://github.com/PHPOffice/PhpSpreadsheet/security/advisories/GHSA-6hq5-7373-42rg
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
