CVE-2026-3463

high

Description

A weakness has been identified in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::binary_writer::append of the file source/detail/binary.hpp of the component Compound Document Parser. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. Patch name: 147. It is suggested to install a patch to address this issue.

References

https://vuldb.com/?submit.764643

https://vuldb.com/?id.348530

https://vuldb.com/?ctiid.348530

https://github.com/xlnt-community/xlnt/pull/147

https://github.com/xlnt-community/xlnt/issues/138#issuecomment-3868381672

https://github.com/xlnt-community/xlnt/issues/138

https://github.com/xlnt-community/xlnt/

https://github.com/oneafter/0128/blob/main/xl2/repro

Details

Source: Mitre, NVD

Published: 2026-03-03

Updated: 2026-03-03

Risk Information

CVSS v2

Base Score: 1.7

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:P

Severity: Low

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High