CVE-2026-3663

A vulnerability was found in xlnt-community xlnt up to 1.6.1. This issue affects the function xlnt::detail::compound_document_istreambuf::xsgetn of the file source/detail/cryptography/compound_document.cpp of the component XLSX File Parser. Performing a manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit has been made public and could be used. The patch is named 147. It is recommended to apply a patch to fix this issue.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:xlnt-community:xlnt:*:*:*:*:*:*:*:*

History

10 Mar 2026, 20:29

Type Values Removed Values Added
References () https://github.com/oneafter/0128/blob/main/xl3/repro - () https://github.com/oneafter/0128/blob/main/xl3/repro - Exploit
References () https://github.com/xlnt-community/xlnt/ - () https://github.com/xlnt-community/xlnt/ - Product
References () https://github.com/xlnt-community/xlnt/issues/139 - () https://github.com/xlnt-community/xlnt/issues/139 - Exploit, Issue Tracking, Vendor Advisory
References () https://github.com/xlnt-community/xlnt/pull/147 - () https://github.com/xlnt-community/xlnt/pull/147 - Issue Tracking
References () https://vuldb.com/?ctiid.349552 - () https://vuldb.com/?ctiid.349552 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.349552 - () https://vuldb.com/?id.349552 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.764644 - () https://vuldb.com/?submit.764644 - Third Party Advisory, VDB Entry
Summary
  • (es) Se encontró una vulnerabilidad en xlnt-community xlnt hasta la versión 1.6.1. Este problema afecta a la función xlnt::detail::compound_document_istreambuf::xsgetn del archivo source/detail/cryptography/compound_document.cpp del componente XLSX File Parser. Realizar una manipulación resulta en una lectura fuera de límites. El ataque solo es posible con acceso local. El exploit se ha hecho público y podría ser utilizado. El parche se llama 147. Se recomienda aplicar un parche para solucionar este problema.
CPE cpe:2.3:a:xlnt-community:xlnt:*:*:*:*:*:*:*:*
First Time Xlnt-community xlnt
Xlnt-community

07 Mar 2026, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-07 15:15

Updated : 2026-03-10 20:29


NVD link : CVE-2026-3663

Mitre link : CVE-2026-3663

CVE.ORG link : CVE-2026-3663


JSON object : View

Products Affected

xlnt-community

  • xlnt
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-125

Out-of-bounds Read