CVE-2025-22131 is a cross-site scripting vulnerability in PhpSpreadsheet, a PHP library for reading and writing spreadsheet files. The issue affects the code path that converts XLSX workbooks into an HTML representation for display in an HTTP response. Based on the provided advisory, the flaw is in HTML generation for multi-sheet workbooks, specifically in navigation generation and sheet title handling, where sheet names are embedded into HTML without proper output encoding or sanitization. An attacker can supply a crafted XLSX file containing a malicious worksheet name so that, when the application processes the file and renders the generated HTML, attacker-controlled script executes in the victim's browser.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (POC) exploit for CVE-2025-22131, an XSS vulnerability. It contains two files: a README.md describing the exploit and a Python script (generate.py) that automates the creation of a malicious Excel file. The script takes a user-supplied HTML/JavaScript payload, escapes it, and injects it into the 'workbook.xml' file inside a sample Excel spreadsheet (sample.xlsx) by replacing the string 'Sheet2' with the payload. The modified files are then re-packaged into 'exploit.xlsx', which can be used to trigger XSS in a vulnerable application that processes the file. The exploit requires a sample Excel file ('sample.xlsx') to function, and the main attack vector is local file manipulation for subsequent delivery to a target. No network endpoints or remote services are involved. The repository is structured simply, with the Python script serving as the main entry point and the README providing usage instructions.
This repository provides a proof-of-concept (PoC) exploit for CVE-2025-22131, a cross-site scripting (XSS) vulnerability in PHPOffice's PhpSpreadsheet library. The vulnerability arises from improper sanitization of sheet names in XLSX files, allowing an attacker to inject arbitrary HTML/JavaScript. The repository contains two files: a README.md with detailed exploitation steps and a Bash script (gen.sh) that automates the process of injecting a malicious sheet name into an XLSX file. The exploit works by unzipping a legitimate XLSX file, modifying the sheet name in 'xl/workbook.xml' to include a JavaScript payload (e.g., an <img> tag with an onerror handler), and re-zipping the file. When the malicious file is uploaded to a vulnerable server and viewed by a victim, the JavaScript executes in the victim's browser, exfiltrating cookies to an attacker-controlled URL. The repository is a clear PoC, requiring manual or semi-automated steps, and does not include a weaponized or fully automated attack chain.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.