Executive brief
Univer is a spreadsheet and document collaboration platform. A remote code execution vulnerability in its formula registration service allows attackers to execute arbitrary code by injecting malicious function payloads through the public API. In server-side Node.js deployments, this could lead to full system compromise with file system and process access.
Technical details
The RemoteRegisterFunctionService in packages/sheets-formula/src/services/remote/remote-register-function.service.ts uses new Function() to deserialize and execute user-supplied function strings transmitted via RPC without validation. An attacker exploits this by providing a malicious toString() override on a function object passed to the public univerAPI.registerFunction() facade API; the serialized malicious code executes in the remote process (Web Worker or Node.js child process) with no sandbox or integrity checks.
Affected products
- Univer Univer v1.0.0-alpha.2
Timeline
- 2026-09-07: disclosed: Vulnerability reported on GitHub
- 2026-09-21: advisory: Published on NVD as CVE-2026-88405