{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aphpofficephpspreadsheet/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:phpoffice:phpspreadsheet:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":6.1,"id":"CVE-2025-22131"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PhpSpreadsheet (\u003c 1.29.8, 2.0.0 - 2.3.6, 3.0.0 - 3.8.0)"],"_cs_severities":["low"],"_cs_tags":["xss","web-vulnerability","php"],"_cs_type":"advisory","_cs_vendors":["PHPOffice"],"content_html":"\u003cp\u003eCVE-2025-22131 is a stored cross-site scripting (XSS) vulnerability affecting the PHPOffice PhpSpreadsheet library (versions \u0026lt; 1.29.8, 2.0.0 through \u0026lt; 2.3.6, and 3.0.0 through \u0026lt; 3.8.0). The vulnerability resides in the \u003ccode\u003egenerateNavigation()\u003c/code\u003e method, which constructs HTML navigation tabs for multi-sheet XLSX files. The library fails to properly sanitize the sheet title returned by \u003ccode\u003e$sheet-\u0026gt;getTitle()\u003c/code\u003e before embedding it directly into the HTML output.\u003c/p\u003e\n\u003cp\u003eAn attacker can exploit this by crafting an XLSX file with multiple sheets where one of the sheet names contains a malicious JavaScript payload. When an application using this library renders the spreadsheet navigation for a victim user, the payload executes in the context of the victim's browser session. This can be used to exfiltrate sensitive data, such as session cookies, to an attacker-controlled server. The availability of a public Proof-of-Concept (PoC) increases the risk of exploitation for applications that process untrusted user-uploaded XLSX files.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker creates a legitimate XLSX file with at least two sheets.\u003c/li\u003e\n\u003cli\u003eAttacker modifies the internal XML structure of the XLSX file (e.g., \u003ccode\u003exl/workbook.xml\u003c/code\u003e) to inject a JavaScript payload into a sheet name field.\u003c/li\u003e\n\u003cli\u003eAttacker re-packages the modified file as a valid XLSX archive.\u003c/li\u003e\n\u003cli\u003eAttacker uploads the malicious XLSX file to a target application that uses the vulnerable PhpSpreadsheet library.\u003c/li\u003e\n\u003cli\u003eThe target application processes the XLSX file using the \u003ccode\u003egenerateNavigation()\u003c/code\u003e method.\u003c/li\u003e\n\u003cli\u003eThe application renders the malicious sheet name directly into an \u003ccode\u003e\u0026lt;a\u0026gt;\u003c/code\u003e tag within the navigation HTML.\u003c/li\u003e\n\u003cli\u003eA victim user views the rendered spreadsheet navigation, triggering the stored XSS payload in their browser.\u003c/li\u003e\n\u003cli\u003eThe payload exfiltrates the victim's session cookies to an attacker-controlled destination.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary JavaScript execution in the context of the victim's browser. This enables attackers to perform unauthorized actions on behalf of the user, exfiltrate sensitive data including session cookies, or potentially hijack active user sessions. The scope of impact is limited to users who view the generated navigation HTML for an uploaded malicious spreadsheet.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the PHPOffice PhpSpreadsheet library to versions 1.29.8, 2.3.6, 3.8.0, or later to incorporate the vendor's patch.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation on all user-uploaded XLSX files, ensuring that sheet names comply with expected naming conventions before they are processed by the library.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not possible, implement Content Security Policy (CSP) headers that restrict inline script execution to mitigate the impact of potential XSS attacks.\u003c/li\u003e\n\u003cli\u003eReview application logs for anomalous POST requests to document upload endpoints, focusing on files that contain suspicious characters (e.g., \u003ccode\u003e\u0026lt;script\u0026gt;\u003c/code\u003e, \u003ccode\u003eonerror\u003c/code\u003e, \u003ccode\u003eonload\u003c/code\u003e) within their internal XML metadata.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-02T20:39:45Z","date_published":"2026-10-02T20:39:45Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2025-22131/","summary":"CVE-2025-22131 is a stored cross-site scripting vulnerability in PHPOffice PhpSpreadsheet caused by improper sanitization of XLSX sheet names in navigation HTML, allowing for session cookie theft.","title":"Stored XSS Vulnerability in PhpSpreadsheet","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2025-22131/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:phpoffice:phpspreadsheet:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}