CVE-2024-45291Disclosure(phpoffice / phpspreadsheet)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file that links images from arbitrary paths. When embedding images has been enabled in HTML writer with `$writer->setEmbedImages(true);` those files will be included in the output as `data:` URLs, regardless of the file's type. Also URLs can be used for embedding, resulting in a Server-Side Request Forgery vulnerability. When embedding images has been enabled, an attacker can read arbitrary files on the server and perform arbitrary HTTP GET requests. Note that any PHP protocol wrappers can be used, meaning that if for example the `expect://` wrapper is enabled, also remote code execution is possible. This issue has been addressed in release versions 1.29.2, 2.1.1, and 2.3.0. All users are advised to upgrade. there are no known workarounds for this vulnerability.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-36CWE-918CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • phpspreadsheet

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
phpspreadsheet

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-29: 1Technical Details · 2026-04-29: 104-29
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • DailyCVE@dailycve
    Disclosure

    🔴 PhpSpreadsheet, PHP Wrapper SSRF/Local File Inclusion → RCE, #CVE-2024-45291 (Critical) https://dailycve.com/phpspreadsheet-php-wrapper-ssrf-local-file-inclusion-%e2%86%92-rce-cve-2024-45291-critical/

    Post summary

    The post discloses a critical SSRF/Local File Inclusion vulnerability in PhpSpreadsheet (CVE‑2024‑45291) that can result in remote code execution.

    0000035
    190 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appphpofficephpspreadsheet---

Explore more