go package report

Is excelize:excelize safe?

1 known vulnerability.

// reach

0 direct dependencies

none carry a known advisory

    0 packages depend on it

    an advisory here reaches each of them

      Create a free accountfor every dependency path, dependent and what to upgrade
      // ai model usage

      Tracked for PyPI packages. HuggingFace models declare Python dependencies, so go packages are not covered.


      cvss
      0.0
      medium

      severity out of 10

      epss
      0.00%
      medium

      chance of exploitation in 30 days, 49th percentile of all CVEs

      xyz score
      0.0
      low

      CyberXYZ composite out of 10

      fig. 01 — CVE-2026-59162, the advisory selected below

      // 1 advisories

      CVE-2026-59162

      UNKNOWN
      // summary

      Excelize parses shared-string cell values with strconv.Atoi and checks only the upper bound before indexing the shared string slice. If an XLSX file contains a shared-string cell with -1, the parsed index is negative. The upper-bound check still passes (len(sharedStrings) > -1), and Excelize indexes sharedStrings[-1], causing a runtime panic.

      This was reproduced on the current default branch commit 1213a8bd7c5a and the latest release tag v2.10.1 (5ad5ab3af005). The issue is independent from the row-bound allocation report, so I am reporting it separately.

      // affected package
      • Package: github.com/xuri/excelize/v2
      • Tested affected versions: current default branch at 1213a8bd7c5a, and release v2.10.1
      • Fixed version: none known at the time of this report
      // impact

      An attacker who can provide an XLSX file to an application using Excelize can trigger a process panic when the application reads the malicious cell through common APIs such as GetCellValue or GetRows. In services that parse untrusted spreadsheets without a panic recovery boundary, this can cause denial of service.

      // root cause

      For shared-string cells (t="s"), xlsxC.getValueFrom() parses the cell value as a shared-string index and only checks whether the index is below len(d.SI) before indexing:

      xlsxSI, _ := strconv.Atoi(strings.TrimSpace(c.V))
      if len(d.SI) > xlsxSI {
          return d.SI[xlsxSI].String(), nil
      }

      For xlsxSI == -1, len(d.SI) > -1 is true, so the code proceeds to index d.SI[-1] and panics.

      // minimal worksheet payload
        
          -1
        

      The workbook also contains a normal sharedStrings.xml with one string (ok), so the failure is specifically due to accepting a negative index.

      // reproduction

      Calling GetCellValue("Sheet1", "A1") on the workbook panics:

      == negative shared string GetCellValue ==
      elapsed=0s alloc_delta=0MB
      PANIC: runtime.boundsError runtime error: index out of range [-1]

      Calling GetRows("Sheet1") on the same workbook also panics:

      == negative shared string GetRows ==
      elapsed=0s alloc_delta=0MB
      PANIC: runtime.boundsError runtime error: index out of range [-1]

      The same results were observed on current default branch commit 1213a8bd7c5a and on release v2.10.1.

      // expected behavior

      Malformed shared-string indices should be rejected or treated as missing/invalid string references without panicking.

      // suggested remediation

      Check both lower and upper bounds before indexing the shared string table. For example:

      if xlsxSI >= 0 && xlsxSI ` value is negative.
      // cvss v4.0 vector

      CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

      Attack vector
      Network
      Attack complexity
      Low
      Attack requirements
      None
      Privileges required
      None
      User interaction
      None
      Confidentiality (vulnerable system)
      None
      Integrity (vulnerable system)
      None
      Availability (vulnerable system)
      Low
      Confidentiality (subsequent systems)
      None
      Integrity (subsequent systems)
      None
      Availability (subsequent systems)
      None

      Checked 2026-09-26 at 20:43 UTC. The most recent advisory here was published 2026-07-10. Updated continuously from NVD, GHSA, OSV and CNA feeds.

      Think a verdict here is wrong? Tell us — we respond within 2 business days.