CVE-2026-45034 affects PhpSpreadsheet prior to version 1.30.5. The vulnerability is a bypass of the earlier CVE-2026-34084 fix in File::prohibitWrappers. The helper attempted to block dangerous PHP stream wrappers by calling parse_url($filename, PHP_URL_SCHEME) and rejecting the path only when the returned scheme satisfied is_string($scheme) && strlen($scheme) > 1. This logic is incomplete because it does not reliably determine whether a path contains a wrapper. For inputs such as phar:///path/file.phar/inner, with three or more slashes after the scheme, parse_url returns false rather than the scheme string. As a result, the wrapper check is skipped and the path is accepted. PHP still interprets phar:///... as a valid phar stream wrapper, so IOFactory::load($attackerPath) can access the phar resource despite the intended protection. On PHP 7.x, merely reaching the phar wrapper through file operations such as is_file can trigger automatic deserialization of phar metadata, invoking attacker-controlled magic methods such as __wakeup and __destruct. On PHP 8.x, automatic metadata deserialization for ordinary file operations was removed, so the issue at the PhpSpreadsheet layer is reduced to a phar-wrapper file-read primitive unless downstream code later performs unsafe metadata access such as Phar::getMetadata.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a small exploit kit for alleged CVE-2026-45034 targeting PHPOffice PHPSpreadsheet PHAR deserialization via phar:// wrapper abuse. Structure: (1) CVE-2026-45034.py is the main Python exploit that checks for local PHP/Composer, generates a malicious PHAR using a temporary PHP script, then POSTs it to a default PHPSpreadsheet sample endpoint with filename set to a phar:// path; (2) xploit.py is a more flexible exploit variant supporting custom URL, endpoint, and command, with optional phpggc integration for a Guzzle/RCE1 gadget chain and a fallback manual PHAR generator; (3) main.py is a lightweight scanner that probes several common upload/import paths for likely vulnerable endpoints; (4) CVE-2026-45034.yaml is a Nuclei template that sends a multipart POST to /vendor/phpoffice/phpspreadsheet/samples/index.php and matches on HTTP 200 plus body words, making this repository partly framework-based; (5) README.md describes the vulnerability and affected versions. Main exploit capability is unauthenticated web-based upload plus deserialization trigger leading to possible RCE. Fingerprintable targets are mostly relative web paths rather than hardcoded hosts. The code disables TLS verification and uses common upload field names and trigger parameters, indicating practical offensive intent. Although the repository claims RCE, success depends heavily on target-specific endpoint behavior and presence of a valid gadget chain, so some components also function as detection or validation aids.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.