Junglewise Threat Intelligence

CVE-2026-88405: Univer RemoteRegisterFunctionService code execution

CVE-2026-88405 · Severity: critical · CVSS 9.8 · Published 2026-09-21

Executive brief

Univer is a spreadsheet and document collaboration platform. A remote code execution vulnerability in its formula registration service allows attackers to execute arbitrary code by injecting malicious function payloads through the public API. In server-side Node.js deployments, this could lead to full system compromise with file system and process access.

Technical details

The RemoteRegisterFunctionService in packages/sheets-formula/src/services/remote/remote-register-function.service.ts uses new Function() to deserialize and execute user-supplied function strings transmitted via RPC without validation. An attacker exploits this by providing a malicious toString() override on a function object passed to the public univerAPI.registerFunction() facade API; the serialized malicious code executes in the remote process (Web Worker or Node.js child process) with no sandbox or integrity checks.

Affected products

  • Univer Univer v1.0.0-alpha.2

Timeline

  • 2026-09-07: disclosed: Vulnerability reported on GitHub
  • 2026-09-21: advisory: Published on NVD as CVE-2026-88405

References

Related threats