CVE-2026-107225
Received Received - Intake

Path Traversal in Excelize Go Library

Vulnerability report for CVE-2026-107225, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.0 to 2.11.0, GetStyle's fill, border, and font extraction predicates check only upper bounds for attacker-controlled style-table indices. File.GetStyle relies on extractStyleCondFuncs predicates that allow negative FillID, BorderID, and FontID values to reach slice indexing. When a crafted styles.xml supplies a negative fillId, borderId, or fontId and the application reads the style, a negative identifier passes the upper-bound-only predicate and becomes a negative slice index, allowing an attacker to panic while reading cell styling. No fixed version is available as of this review.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
qax-os excelize >= 2.8.0, <= 2.11.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-129 The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Excelize Go library for reading and writing Excel files. It allows a crafted Excel file to cause a crash by including negative values for style identifiers like fillId, borderId, or fontId. The library fails to validate these negative values properly, leading to negative array indices and a panic when reading cell styles.

Detection Guidance

To detect this vulnerability, inspect Go applications using Excelize versions 2.8.0 to 2.11.0. Check for crashes when processing Excel files with negative fillId, borderId, or fontId values in styles.xml. No direct commands are provided, but monitoring for application panics during file processing may indicate exploitation.

Impact Analysis

If you use the Excelize library in versions 2.8.0 to 2.11.0, opening a malicious Excel file could crash your application. This causes a denial of service by making the program unavailable until restarted. No data theft or corruption occurs, but the application stops functioning normally.

Compliance Impact

This vulnerability primarily impacts system availability by causing crashes when processing maliciously crafted Excel files. It does not directly lead to data breaches or unauthorized access, which are common compliance concerns under GDPR or HIPAA. However, repeated crashes could disrupt operations handling sensitive data, potentially affecting service availability requirements in regulated environments.

Mitigation Strategies

Upgrade to Excelize version 2.11.1 or later if available. If upgrading is not possible, implement lower-bound checks for style indices (fillID, borderID, fontID) in your code to ensure they are non-negative before accessing arrays. Validate all input files for negative style indices.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107225. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart