CVE-2026-3665 | xlnt-community xlnt up to 1.6.1 XLSX File Parser xlsx_consumer.cpp read_office_document null pointer dereference (Issue 140 / EUVD-2026-10173)
A vulnerability, which was classified as problematic, has been found in xlnt-community xlnt up to 1.6.1. The affected element is the function xlnt::detail::xlsx_consumer::read_office_document of the file source/detail/serialization/xlsx_consumer.cpp of the component XLSX File Parser. The manipulation leads to null pointer dereference.
This vulnerability is listed as CVE-2026-3665. The attack must be carried out locally. In addition, an exploit is available.