CVE-2023-7101: Spreadsheet::ParseExcel Remote Code Execution Vulnerability

High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2024-01-02. EPSS: 19.1% chance of exploitation in the next 30 days.

Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Fedoraproject Fedora: version 38 only; version 39 only
  • Jmcnamara Spreadsheet::ParseExcel: up to and including 0.65

Published 2023-12-24. Last modified 2026-06-17.