Stored XSS Vulnerability in PhpSpreadsheet
CVE-2025-22131 is a stored cross-site scripting vulnerability in PHPOffice PhpSpreadsheet caused by improper sanitization of XLSX sheet names in navigation HTML, allowing for session cookie theft.
CVE search metadata
CVE search record: CVE-2025-22131. Severity: medium. CVSS: 6.1. EPSS: 0.38%. KEV: no. Product: PhpSpreadsheet (< 1.29.8, 2.0.0 - 2.3.6, 3.0.0 - 3.8.0). Brief: Stored XSS Vulnerability in PhpSpreadsheet. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2025-22131/
CVE-2025-22131 is a stored cross-site scripting (XSS) vulnerability affecting the PHPOffice PhpSpreadsheet library (versions < 1.29.8, 2.0.0 through < 2.3.6, and 3.0.0 through < 3.8.0). The vulnerability resides in the generateNavigation() method, which constructs HTML navigation tabs for multi-sheet XLSX files. The library fails to properly sanitize the sheet title returned by $sheet->getTitle() before embedding it directly into the HTML output.
An attacker can exploit this by crafting an XLSX file with multiple sheets where one of the sheet names contains a malicious JavaScript payload. When an application using this library renders the spreadsheet navigation for a victim user, the payload executes in the context of the victim's browser session. This can be used to exfiltrate sensitive data, such as session cookies, to an attacker-controlled server. The availability of a public Proof-of-Concept (PoC) increases the risk of exploitation for applications that process untrusted user-uploaded XLSX files.
Attack Chain
- Attacker creates a legitimate XLSX file with at least two sheets.
- Attacker modifies the internal XML structure of the XLSX file (e.g.,
xl/workbook.xml) to inject a JavaScript payload into a sheet name field. - Attacker re-packages the modified file as a valid XLSX archive.
- Attacker uploads the malicious XLSX file to a target application that uses the vulnerable PhpSpreadsheet library.
- The target application processes the XLSX file using the
generateNavigation()method. - The application renders the malicious sheet name directly into an
<a>tag within the navigation HTML. - A victim user views the rendered spreadsheet navigation, triggering the stored XSS payload in their browser.
- The payload exfiltrates the victim's session cookies to an attacker-controlled destination.
Impact
Successful exploitation allows for arbitrary JavaScript execution in the context of the victim's browser. This enables attackers to perform unauthorized actions on behalf of the user, exfiltrate sensitive data including session cookies, or potentially hijack active user sessions. The scope of impact is limited to users who view the generated navigation HTML for an uploaded malicious spreadsheet.
Recommendation
- Upgrade the PHPOffice PhpSpreadsheet library to versions 1.29.8, 2.3.6, 3.8.0, or later to incorporate the vendor's patch.
- Implement strict input validation on all user-uploaded XLSX files, ensuring that sheet names comply with expected naming conventions before they are processed by the library.
- If immediate patching is not possible, implement Content Security Policy (CSP) headers that restrict inline script execution to mitigate the impact of potential XSS attacks.
- Review application logs for anomalous POST requests to document upload endpoints, focusing on files that contain suspicious characters (e.g.,
<script>,onerror,onload) within their internal XML metadata.
Immediate actions
Upgrade PhpSpreadsheet to 1.29.8, 2.3.6, or 3.8.0
Mitigations
Implement Content Security Policy (CSP) to restrict script execution.
CVE-2025-22131