PhpSpreadsheet RCE Vulnerability: PoC Exploit Disclosed for 312 Million Users
ID: a596fa58-837e-5949-830f-445dc582f6d5
STIX ID: report--a596fa58-837e-5949-830f-445dc582f6d5
Feed Name: securityonline.info
PhpSpreadsheet (widely used PHP library) has a critical RCE vulnerability CVE-2026-45034: a logic flaw in File::prohibitWrappers uses parse_url and can be bypassed with three-or-more-slash paths (e.g., phar:///...), allowing PHP to open phar wrappers. The impact includes automatic deserialization and full RCE on PHP 7.x, reduced to a file-read primitive on PHP 8.x unless the application later invokes Phar::getMetadata. A public proof-of-concept exists, all 1.x versions up to 1.30.4 are vulnerable, and users should upgrade to 1.30.5 and avoid parse_url-based wrapper checks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
