Back

HIGH KEV

Arbitrary Code Execution (ACE) Vulnerability

Published Dec 24, 2023 ·Due Jan 23, 2024

Description

Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic.

Affected products

Remediation

Vendor solution

Update to version 0.66

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Mandiant
Published Dec 24, 2023
Updated Oct 21, 2025
Reserved Dec 24, 2023
CISA Vulnrichment
Updated Aug 20, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a