Executive brief
PhpSpreadsheet is a library used by web applications to read and write spreadsheet files like Excel. A security flaw in its HTML conversion tool allows an attacker to bypass security filters by using specific cell formatting. If an application converts a malicious user-uploaded spreadsheet into a web page, it could execute unauthorized scripts in the browsers of other users, potentially leading to account hijacking or data theft.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in PhpSpreadsheet's HTML writer component. The vulnerability is caused by a conditional check in `Writer/Html.php` that only applies `htmlspecialchars()` escaping if the formatted cell data is identical to the original data. By using a custom number format containing the '@' text placeholder with additional literal characters (e.g., ". @"), an attacker can ensure the formatted value differs from the original, bypassing the escaping logic entirely. An attacker can exploit this by uploading a spreadsheet with a malicious XSS payload in a cell and a specific number format; when the library converts this to HTML, the payload is rendered unescaped. This issue is resolved in versions 5.7.0, 3.10.5, 2.4.5, 2.1.16, and 1.30.4.
Affected products
- PHPOffice PhpSpreadsheet < 1.30.4, 2.0.0 - 2.1.15, 2.2.0 - 2.4.4, 3.3.0 - 3.10.4, 4.0.0 - 5.6.0
Timeline
- 2026-04-26: advisory: GitHub Security Advisory published by maintainer
- 2026-05-06: disclosed: CVE-2026-40296 published