Go Library for Excel Spreadsheets Exposes Security Issue in Style Index Extraction
CVE-2026-107225

6.5MEDIUM

Key Information:

Vendor

Qax-os

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-107225?

The Excelize Go library, which enables reading and writing of Microsoft Excel files, has a vulnerability affecting versions 2.8.0 through 2.11.0. This issue arises from inadequate validation in the GetStyle method, specifically in its handling of style-table indices. Attackers can exploit this flaw by providing negative values for FillID, BorderID, or FontID. Consequently, when these values are used to index slices, they can lead to out-of-bounds errors, causing the application to crash while attempting to read cell styling from a crafted styles.xml file. Currently, no fixes are available, putting applications using this library at risk.

Affected Version(s)

excelize >= 2.8.0, <= 2.11.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.