CVE Tools
Back to feed
PoC public PhpSpreadsheet rce PHPOffice web-app

PhpSpreadsheet RCE Vulnerability: PoC Exploit Disclosed for 312 Million Users

Daily CyberSecurity (securityonline.info)·By Do Son··2 min read
CVE Tools coverage

A critical remote code execution issue tracked as CVE-2026-45034 has been disclosed in PhpSpreadsheet (PHPOffice), along with public proof-of-concept exploit details. The problem stems from a patch-bypass weakness in File::prohibitWrappers that attackers can evade by manipulating wrapper input, allowing dangerous file handling and, depending on the PHP version and application behavior, potential deserialization to reach RCE. Versions in the 1.x series up to 1.30.4 are reported as vulnerable, and upgrading to 1.30.5 is recommended to reduce exposure.