AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-107225.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 07, 2026

Disclosure summary

## Summary `File.GetStyle` indexes the fill, border and font tables with values taken straight out of `xl/styles.xml`, and the conditions gating those lookups check only the upper bound. A workbook whose `cellXfs` entry carries `fillId="-1"`, `borderId="-1"` or `fontId="-1"` reaches a negative slice index and panics. excelize has no `recover()`, so the panic leaves `GetStyle` and takes the calling process with it. Same defect class as GHSA-48hm-4h8j-58fg, the negative shared-string index, in a different file. That one was fixed by adding the missing lower bound; these three sites still lack it. ## Where it is `styles.go`, in `GetStyle`, lines 1683, 1686 and 1689: ```go xf := s.CellXfs.Xf[idx] if extractStyleCondFuncs["fill"](xf, s) { f.extractFills(s.Fills.Fill[*xf.FillID], s, style) } if extractStyleCondFuncs["border"](xf, s) { f.extractBorders(s.Borders.Border[*xf.BorderID], s, style) } if extractStyleCondFuncs["font"](xf, s) { style.Font = extractFont(s.Fonts.Font[*xf.FontID]) } ``` The conditions, at lines 1171 to 1185, bound only the top: ```go "fill": func(xf xlsxXf, s *xlsxStyleSheet) bool { return (xf.ApplyFill == nil || (xf.ApplyFill != nil && *xf.ApplyFill)) && xf.FillID

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-5h23-36rv-pm65

Open original source · Updated Oct 07, 2026

Excelize: GetStyle panics on a negative fillId, borderId or fontId in styles.xml

Source severity: MEDIUM / 0

EcosystemPackageAffected rangeFirst patched
gogithub.com/xuri/excelize/v2>= 2.8.0, < 2.11.1-0.20260731010303-ae2113b410e52.11.1-0.20260731010303-ae2113b410e5

Original records & references

PUBLISHED 2026-10-07T16:22:39-04:00
MODIFIED 2026-10-07T16:22:41-04:00
INGESTED 2026-10-08T12:30:38-04:00