CVE-2026-3663 | xlnt-community xlnt up to 1.6.1 XLSX File Parser compound_document.cpp xsgetn out-of-bounds (Issue 139 / ID 147)
A vulnerability classified as problematic has been found in xlnt-community xlnt up to 1.6.1. This issue affects the function xlnt::detail::compound_document_istreambuf::xsgetn of the file source/detail/cryptography/compound_document.cpp of the component XLSX File Parser. Performing a manipulation results in out-of-bounds read.
This vulnerability is identified as CVE-2026-3663. The attack is only possible with local access. Additionally, an exploit exists.
It is recommended to apply a patch to fix this issue.