Go Library for Excel Spreadsheets Exposes Security Issue in Style Index Extraction
CVE-2026-107225
6.5MEDIUM
What is CVE-2026-107225?
The Excelize Go library, which enables reading and writing of Microsoft Excel files, has a vulnerability affecting versions 2.8.0 through 2.11.0. This issue arises from inadequate validation in the GetStyle method, specifically in its handling of style-table indices. Attackers can exploit this flaw by providing negative values for FillID, BorderID, or FontID. Consequently, when these values are used to index slices, they can lead to out-of-bounds errors, causing the application to crash while attempting to read cell styling from a crafted styles.xml file. Currently, no fixes are available, putting applications using this library at risk.
Affected Version(s)
excelize >= 2.8.0, <= 2.11.0
