Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-45034— PhpSpreadsheet: File::prohibitWrappers bypass

Quick assessment

Affected
PHPOffice PhpSpreadsheet
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

PHPOffice PhpSpreadsheet是PHPOffice组织开源的一款用于读取和写入电子表格文件的PHP库。 PHPOffice PhpSpreadsheet 1.30.5之前版本存在反序列化注入漏洞,该漏洞源于File::prohibitWrappers辅助函数中parse_url函数对带有三个或以上斜杠的phar:///格式调用返回false,从而绕过流包装器检查,可能导致通过phar元数据自动反序列化触发远程代码执行。

AI Predicted 9.8 Difficulty: Easy EPSS 0.46% · P38

Affected Version Matrix 1

VendorProduct Version RangeStatus
PHPOffice PhpSpreadsheet < 1.30.5 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-45034

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
PhpSpreadsheet: File::prohibitWrappers bypass
Source: CVE Program / CVE List V5
Vulnerability Description
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patched by the helper File::prohibitWrappers. The helper calls parse_url($filename, PHP_URL_SCHEME) and then checks is_string($scheme) && strlen($scheme) > 1 to reject stream wrappers such as phar://, php://, data:// or expect://. The check is not equivalent to "does the path contain a wrapper". When the input has the form phar:///path/file.phar/inner with three or more slashes after the scheme, parse_url returns boolean false instead of returning the scheme string. The is_string($scheme) branch is therefore skipped, the helper returns without throwing, and the caller proceeds. PHP's stream layer, however, still treats phar:///... as a valid phar wrapper and opens the underlying phar file. The result is that IOFactory::load($attackerPath) walks past the patch and still touches the phar wrapper. On PHP 7.x, simply reaching the phar wrapper via is_file is enough for PHP to automatically deserialize the phar metadata, which in turn invokes the magic methods __wakeup and __destruct of an attacker controlled object and gives full RCE. On PHP 8.x, automatic metadata deserialization for plain file ops was removed, so the chain at the PhpSpreadsheet layer reduces to a phar wrapper file read primitive, and RCE only resurfaces if the downstream consumer ever calls Phar::getMetadata. This vulnerability is fixed in 1.30.5.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
可信数据的反序列化
Source: CVE Program / CVE List V5
Vulnerability Title
PHPOffice PhpSpreadsheet 反序列化注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
PHPOffice PhpSpreadsheet是PHPOffice组织开源的一款用于读取和写入电子表格文件的PHP库。 PHPOffice PhpSpreadsheet 1.30.5之前版本存在反序列化注入漏洞,该漏洞源于File::prohibitWrappers辅助函数中parse_url函数对带有三个或以上斜杠的phar:///格式调用返回false,从而绕过流包装器检查,可能导致通过phar元数据自动反序列化触发远程代码执行。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
PHPOffice PhpSpreadsheet < 1.30.5 -

II. Public POCs for CVE-2026-45034

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-45034

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-45034 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-45034

No comments yet


Leave a comment