{"id":6517,"date":"2025-08-29T10:03:37","date_gmt":"2025-08-29T10:03:37","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/29\/phpspreadsheet-library-vulnerability-enables-attackers-to-feed-malicious-html-input\/"},"modified":"2025-08-29T10:03:37","modified_gmt":"2025-08-29T10:03:37","slug":"phpspreadsheet-library-vulnerability-enables-attackers-to-feed-malicious-html-input","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/29\/phpspreadsheet-library-vulnerability-enables-attackers-to-feed-malicious-html-input\/","title":{"rendered":"PhpSpreadsheet Library Vulnerability Enables Attackers to Feed Malicious HTML Input"},"content":{"rendered":"<p>    PhpSpreadsheet Library Vulnerability Enables Attackers to Feed Malicious HTML Input<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A high-severity Server-Side Request Forgery (SSRF) vulnerability has been identified in the widely used PhpSpreadsheet library, potentially allowing attackers to exploit internal network resources and compromise server security.\u00a0<\/p>\n<p>The vulnerability, tracked as CVE-2025-54370, affects multiple versions of the phpoffice\/phpspreadsheet package and carries a CVSS v4.0 score of 8.7.<\/p>\n<pre class=\"wp-block-preformatted\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-cyan-blue-color\"><strong>Key Takeaways<\/strong><br><\/mark>1. SSRF in PhpSpreadsheet\u2019s WorksheetDrawing::setPath via malicious HTML image tags.<br>2. Affects &lt; 1.30.0, 2.0.0\u20132.1.11, 2.2.0\u20132.3.x, 3.0.0\u20133.9.x, 4.x\u2009&lt;\u20095.0.0<br>3. Update immediately and validate inputs.<\/pre>\n<h2 class=\"wp-block-heading\" id=\"h-high-severity-ssrf-vulnerability\"><strong>High-Severity SSRF Vulnerability<\/strong><\/h2>\n<p>The vulnerability resides in the setPath method of the PhpOfficePhpSpreadsheetWorksheetDrawing class, where malicious HTML input can trigger unauthorized server-side requests.\u00a0<\/p>\n<p>Security researcher Aleksey Solovev from Positive Technologies discovered this zero-day flaw while analyzing version 3.8.0 of the library.<\/p>\n<p>The exploitation occurs when attackers craft <a href=\"https:\/\/cybersecuritynews.com\/html-smuggling-ransomware\/\" target=\"_blank\" rel=\"noreferrer noopener\">malicious HTML<\/a> documents containing image tags with src attributes pointing to internal network resources.\u00a0<\/p>\n<p>When the PhpSpreadsheet HTML reader processes these documents, the library inadvertently makes requests to the specified URLs, potentially exposing sensitive internal services.<\/p>\n<p>Proof-of-concept code demonstrates the attack vector:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXfzUoZ4pCveXRIxcLr48Qb4KtIFHCs6guiHzMkXWbwhz5n19IjM4gvJP9GNuwfDdTdxaLXYwjtCJylBjMIeL7BZe3dFUnpm2ycosBirBhDtzeNiWvTLFGDISlWCHosVoN1-wVdAQw?key=RIJX7Rd_m2n0k73dYAGxyQ\" alt=\"PhpSpreadsheet Library Vulnerability\"><\/figure>\n<\/div>\n<p>The malicious HTML file contains:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXcEBgZ4XkmL_uH08MioAdq6xDP8xR_kOizg6NwPlS7BQdhQYrB7dmL2e_IccQ1sqDvRXuSy1PR75Fv4bdCNmAhoINOMEYzk5llJPFLRU3TmVrMJSZtxIdQkD1oncHd-ebFgiBkNZg?key=RIJX7Rd_m2n0k73dYAGxyQ\" alt=\"PhpSpreadsheet Library Vulnerability\"><\/figure>\n<\/div>\n<figure class=\"wp-block-table aligncenter\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>Risk Factors<\/strong><\/td>\n<td><strong>Details<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Affected Products<\/td>\n<td>\u2013 Versions &lt; 1.30.0- 2.0.0\u20132.1.11- 2.2.0\u20132.3.x- 3.0.0\u20133.9.x- 4.x &lt; 5.0.0<\/td>\n<\/tr>\n<tr>\n<td>Impact<\/td>\n<td>High confidentiality impact via SSRF<\/td>\n<\/tr>\n<tr>\n<td>Exploit Prerequisites<\/td>\n<td>Untrusted HTML input passed to the HTML reader<\/td>\n<\/tr>\n<tr>\n<td>CVSS 3.1 Score<\/td>\n<td>7.5 (High)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\" id=\"h-affected-versions-and-security-patches\"><strong>Affected Versions and Security Patches<\/strong><\/h2>\n<p>The vulnerability impacts multiple version ranges across the PhpSpreadsheet ecosystem:<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Legacy versions:<\/strong> All versions prior to 1.30.0<\/li>\n<li>\n<strong>Version 2.x series: <\/strong>2.0.0 through 2.1.11 and 2.2.0 through 2.3.x<\/li>\n<li>\n<strong>Version 3.x series:<\/strong> 3.0.0 through 3.9.x<\/li>\n<li>\n<strong>Version 4.x series: <\/strong>All 4.x versions prior to 5.0.0<\/li>\n<\/ul>\n<p>Patched versions include 1.30.0, 2.1.12, 2.4.0, 3.10.0, and 5.0.0. Organizations using affected versions should prioritize immediate updates to prevent potential exploitation.<\/p>\n<p>The <a href=\"https:\/\/cybersecuritynews.com\/chrome-high-severity-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">vulnerability<\/a> classification follows CWE-918: Server-Side Request Forgery, with attack vectors requiring no <a href=\"https:\/\/cybersecuritynews.com\/authentication\/\" target=\"_blank\" rel=\"noreferrer noopener\">authentication<\/a> or user interaction (AV:N\/AC:L\/PR:N\/UI:N).\u00a0<\/p>\n<p>This enables remote attackers to exploit the flaw through network-accessible applications processing user-supplied HTML content.<\/p>\n<p>Additional security concerns include potential phar deserialization attacks through the file_exists method of the vulnerable code, creating multiple attack surfaces within the same component.\u00a0<\/p>\n<p>Organizations utilizing PhpSpreadsheet for HTML document processing should implement input validation and network segmentation as additional protective measures while deploying the security updates.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong>Find this Story Interesting! Follow us on\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>.<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/phpspreadsheet-library-vulnerability\/\">PhpSpreadsheet Library Vulnerability Enables Attackers to Feed Malicious HTML Input<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Florence Nightingale<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/phpspreadsheet-library-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>PhpSpreadsheet Library Vulnerability Enables Attackers to Feed Malicious HTML Input A high-severity Server-Side Request Forgery (SSRF) vulnerability has been identified in the widely used PhpSpreadsheet library, potentially allowing attackers to exploit internal network resources and compromise server security.\u00a0 The vulnerability, tracked as CVE-2025-54370, affects multiple versions of the phpoffice\/phpspreadsheet package and carries a CVSS v4.0 [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-6517","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6517"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6517"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6517\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6517"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6517"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6517"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}