A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2023-7101

Spreadsheet::ParseExcel Remote Code Execution Vulnerability

Published
2024-01-02
Modified
2026-07-31
Sources
cisa-kev

Summary

Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings within the Excel parsing logic.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.