A AegiFlow
MEDIUMCVSS 6.9EPSS 0.4%

CVE-2026-59162

Excelize: Negative shared-string index causes panic in GetCellValue and GetRows

Published
2026-09-10
Modified
2026-09-10
EPSS percentile
32%
Aliases
GHSA-fx5j-qcqg-grpf
Sources
github-advisory

Summary

# Negative shared-string index causes panic in GetCellValue and GetRows ## Summary Excelize parses shared-string cell values with `strconv.Atoi` and checks only the upper bound before indexing the shared string slice. If an XLSX file contains a shared-string cell with ` -1 `, the parsed index is negative. The upper-bound check still passes (`len(sharedStrings) > -1`), and Excelize indexes `sharedStrings[-1]`, causing a runtime panic. This was reproduced on the current default branch commit `1213a8bd7c5ab360554603ac5c995ccaf6eb4314` and the latest release tag `v2.10.1` (`5ad5ab3af0054c55bdce09f1530085600e9f2e45`). The issue is independent from the row-bound allocation report, so I am reporting it separately. ## Affected package - Package: `github.com/xuri/excelize/v2` - Tested affected versions: current default branch at `1213a8bd7c5ab360554603ac5c995ccaf6eb4314`, and release `v2.10.1` - Fixed version: none known at the time of this report ## Impact An attacker who can provide an XLSX file to an application using Excelize can trigger a process panic when the application reads the malicious cell through common APIs such as `GetCellValue` or `GetRows`. In services that parse untrusted spreadsheets without a panic recovery boundary, this can cause denial of service. ## Root cause For shared-string cells (`t="s"`), `xlsxC.getValueFrom()` parses the cell value as a shared-string index and only checks whether the index is below `len(d.SI)` before indexing: ```go xlsxSI, _ := strconv.Atoi(strings.TrimSpace(c.V)) if len(d.SI) > xlsxSI { return d.SI[xlsxSI].String(), nil } ``` For `xlsxSI == -1`, `len(d.SI) > -1` is true, so the code proceeds to index `d.SI[-1]` and panics. ## Minimal worksheet payload ```xml -1 ``` The workbook also contains a normal `sharedStrings.xml` with one string (`ok`), so the failure is specifically due to accepting a negative index. ## Reproduction Calling `GetCellValue("Sheet1", "A1")` on the workbook panics: ```text == negative shared string GetCellValue == elapsed=0s alloc_delta=0MB PANIC: runtime.boundsError runtime error: index out of range [-1] ``` Calling `GetRows("Sheet1")` on the same workbook also panics: ```text == negative shared string GetRows == elapsed=0s alloc_delta=0MB PANIC: runtime.boundsError runtime error: index out of range [-1] ``` The same results were observed on current default branch commit `1213a8bd7c5ab360554603ac5c995ccaf6eb4314` and on release `v2.10.1`. ## Expected behavior Malformed shared-string indices should be rejected or treated as missing/invalid string references without panicking. ## Suggested remediation Check both lower and upper bounds before indexing the shared string table. For example: ```go if xlsxSI >= 0 && xlsxSI ` value is negative.

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogithub.com/xuri/excelize
Gogithub.com/xuri/excelize/v22.11.0

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.