Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25699 | PhpSpreadsheet vulnerable to SSRF when reading and displaying a processed HTML document in the browser |
Github GHSA |
GHSA-rx7m-68vc-ppxh | PhpSpreadsheet vulnerable to SSRF when reading and displaying a processed HTML document in the browser |
Mon, 25 Aug 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Phpoffice
Phpoffice phpspreadsheet |
|
| Vendors & Products |
Phpoffice
Phpoffice phpspreadsheet |
Mon, 25 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 25 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PhpOffice/PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to versions 1.30.0, 2.1.12, 2.4.0, 3.10.0, and 5.0.0, SSRF can occur when a processed HTML document is read and displayed in the browser. The vulnerability lies in the setPath method of the PhpOffice\PhpSpreadsheet\Worksheet\Drawing class, where a crafted string from the user is passed to the HTML reader. This issue has been patched in versions 1.30.0, 2.1.12, 2.4.0, 3.10.0, and 5.0.0. | |
| Title | PhpSpreadsheet vulnerable to SSRF when reading and displaying a processed HTML document in the browser | |
| Weaknesses | CWE-918 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-25T14:34:39.628Z
Reserved: 2025-07-21T16:12:20.732Z
Link: CVE-2025-54370
Updated: 2025-08-25T14:34:32.955Z
Status : Deferred
Published: 2025-08-25T14:15:33.117
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-54370
No data.
OpenCVE Enrichment
Updated: 2025-08-25T21:53:06Z
EUVD
Github GHSA