logo

PhpSpreadsheet RCE Vulnerability: PoC Exploit Disclosed for 312 Million Users

ID: a596fa58-837e-5949-830f-445dc582f6d5

STIX ID: report--a596fa58-837e-5949-830f-445dc582f6d5

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-06-11

Date Updated: 2026-06-11

Author: Do Son

...
...

PhpSpreadsheet (widely used PHP library) has a critical RCE vulnerability CVE-2026-45034: a logic flaw in File::prohibitWrappers uses parse_url and can be bypassed with three-or-more-slash paths (e.g., phar:///...), allowing PHP to open phar wrappers. The impact includes automatic deserialization and full RCE on PHP 7.x, reduced to a file-read primitive on PHP 8.x unless the application later invokes Phar::getMetadata. A public proof-of-concept exists, all 1.x versions up to 1.30.4 are vulnerable, and users should upgrade to 1.30.5 and avoid parse_url-based wrapper checks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.