CVE-2026-3663Disclosure(xlnt-community / xlnt)

LOWCVSS 7.1 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in xlnt-community xlnt up to 1.6.1. This issue affects the function xlnt::detail::compound_document_istreambuf::xsgetn of the file source/detail/cryptography/compound_document.cpp of the component XLSX File Parser. Performing a manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit has been made public and could be used. The patch is named 147. It is recommended to apply a patch to fix this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-125

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • xlnt

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Products
xlnt

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-07: 3Technical Details · 2026-03-07: 303-07
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-3663 A vulnerability was found in xlnt-community xlnt up to 1.6.1. This issue affects the function xlnt::detail::compound_document_istreambuf::xsgetn of the file source/deta… https://www.cve.org/CVERecord?id=CVE-2026-3663

    Post summary

    A new CVE (CVE-2026-3663) has been disclosed for xlnt-community xlnt up to version 1.6.1, identifying a vulnerability in the xsgetn function. No exploitation, patch, or PoC details are presented.

    00000108
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3663 - xlnt-community xlnt XLSX File compound_document.cpp xsgetn out-of-bounds Intel Report: https://ift.tt/UBV4cnH

    Post summary

    An alert for CVE‑2026‑3663 has been issued, pointing to an out‑of‑bounds issue in xlnt-community’s XLSX handling (compound_document.cpp xsgetn), with a link to an Intel report for further details.

    0000028
    344 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3663 Local Out-of-Bounds Read Vulnerability in xlnt-community XLSX File Parser https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3663

    Post summary

    The passage announces CVE-2026-3663 as a local out-of-bounds read flaw in the xlnt-community XLSX parser, providing only the vulnerability type without any PoC, exploit details, or patch information.

    0000031
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appxlnt-communityxlnt---

Explore more