<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:phpoffice:phpspreadsheet:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aphpofficephpspreadsheet/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 20:39:45 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aphpofficephpspreadsheet/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS Vulnerability in PhpSpreadsheet</title><link>https://feed.craftedsignal.io/briefs/2026-10-cve-2025-22131/</link><pubDate>Fri, 02 Oct 2026 20:39:45 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cve-2025-22131/</guid><description>CVE-2025-22131 is a stored cross-site scripting vulnerability in PHPOffice PhpSpreadsheet caused by improper sanitization of XLSX sheet names in navigation HTML, allowing for session cookie theft.</description><content:encoded><![CDATA[<p>CVE-2025-22131 is a stored cross-site scripting (XSS) vulnerability affecting the PHPOffice PhpSpreadsheet library (versions &lt; 1.29.8, 2.0.0 through &lt; 2.3.6, and 3.0.0 through &lt; 3.8.0). The vulnerability resides in the <code>generateNavigation()</code> method, which constructs HTML navigation tabs for multi-sheet XLSX files. The library fails to properly sanitize the sheet title returned by <code>$sheet-&gt;getTitle()</code> before embedding it directly into the HTML output.</p>
<p>An attacker can exploit this by crafting an XLSX file with multiple sheets where one of the sheet names contains a malicious JavaScript payload. When an application using this library renders the spreadsheet navigation for a victim user, the payload executes in the context of the victim's browser session. This can be used to exfiltrate sensitive data, such as session cookies, to an attacker-controlled server. The availability of a public Proof-of-Concept (PoC) increases the risk of exploitation for applications that process untrusted user-uploaded XLSX files.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker creates a legitimate XLSX file with at least two sheets.</li>
<li>Attacker modifies the internal XML structure of the XLSX file (e.g., <code>xl/workbook.xml</code>) to inject a JavaScript payload into a sheet name field.</li>
<li>Attacker re-packages the modified file as a valid XLSX archive.</li>
<li>Attacker uploads the malicious XLSX file to a target application that uses the vulnerable PhpSpreadsheet library.</li>
<li>The target application processes the XLSX file using the <code>generateNavigation()</code> method.</li>
<li>The application renders the malicious sheet name directly into an <code>&lt;a&gt;</code> tag within the navigation HTML.</li>
<li>A victim user views the rendered spreadsheet navigation, triggering the stored XSS payload in their browser.</li>
<li>The payload exfiltrates the victim's session cookies to an attacker-controlled destination.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for arbitrary JavaScript execution in the context of the victim's browser. This enables attackers to perform unauthorized actions on behalf of the user, exfiltrate sensitive data including session cookies, or potentially hijack active user sessions. The scope of impact is limited to users who view the generated navigation HTML for an uploaded malicious spreadsheet.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade the PHPOffice PhpSpreadsheet library to versions 1.29.8, 2.3.6, 3.8.0, or later to incorporate the vendor's patch.</li>
<li>Implement strict input validation on all user-uploaded XLSX files, ensuring that sheet names comply with expected naming conventions before they are processed by the library.</li>
<li>If immediate patching is not possible, implement Content Security Policy (CSP) headers that restrict inline script execution to mitigate the impact of potential XSS attacks.</li>
<li>Review application logs for anomalous POST requests to document upload endpoints, focusing on files that contain suspicious characters (e.g., <code>&lt;script&gt;</code>, <code>onerror</code>, <code>onload</code>) within their internal XML metadata.</li>
</ol>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>xss</category><category>web-vulnerability</category><category>php</category></item></channel></rss>