Threats Tagged 'ghsa-8mcq-6wmr-jrjv'
View all threats tagged with 'ghsa-8mcq-6wmr-jrjv'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-8mcq-6wmr-jrjv'
Click on any threat for detailed analysis and mitigation recommendations
0 ## Affected versions and vulnerable location - Confirmed at `ae2113b` (current HEAD). - Sink: `rows.go:967` `ws.SheetData.Row[rowIdx].C[colNum-1] = *colData` inside `checkRow`. - `checkRow` computes `lastCol` from the column of the last cell in document order (`rows.go:940`), allocates `targetList` of that length, then re-scatters every source cell into `C[colNum-1]`. ## Root cause The slice is sized from the last cell's column, but cells are not required to be column-sorted in the XML. A cell that appears earlier in the row but references a higher column than the last cell has `colNum-1 >= len(targetList)`, so the assignment writes out of range. `MaxColumns`/`TotalRows` do not help, every individual column is valid; the bug is the ordering assumption, not magnitude. ## Attacker model and reachability Any service that opens an untrusted spreadsheet and calls a worksheet API that goes through `workSheetReader -> checkRow` (`excelize.go:332`): `GetCellValue`, `GetCellFormula`, `CalcCellValue`, `GetMergeCells`, `SetCellValue`, and essentially every non-streaming worksheet call. (The streaming `GetRows`/`Rows()` SAX path does not trigger it.) Unauthenticated, deterministic, unrecovered panic -> process crash. ## Proof of concept (executed) Crafted `xl/worksheets/sheet1.xml` with a row whose cells are out of column order and whose earlier cell exceeds the last cell's column: ```xml <row r="1"><c r="D1"><v>4</v></c><c r="C1"><v>3</v></c></row> ``` `GetCellValue("Sheet1","A1")` (via `getCellStringFunc -> workSheetReader -> checkRow`) panicked `index out of range [3] with length 3` at `rows.go:967`. Confirming grep: ```bash rg -n "func checkRow|lastCol|Row\[rowIdx\].C\[colNum-1\]" rows.go ``` ## Suggested fix Size `targetList` from the maximum cell column in the row (not the last cell in document order), or bounds-check `colNum-1` against `len(targetList)` and grow the slice as needed before the assignment. Join the discussion | CVE Database V5 | 10/07/2026, 20:23:08 UTC Added: 10/07/2026, 18:49:12 UTC |
Showing 1 to 1 of 1 result