CVE-2025-54370 | PHPOffice PhpSpreadsheet up to 1.29.x/2.1.11/2.3.x/3.9.x/4.x HTML Document setPath server-side request forgery (GHSA-rx7m-68vc-ppxh)
A vulnerability labeled as critical has been found in PHPOffice PhpSpreadsheet up to 1.29.x/2.1.11/2.3.x/3.9.x/4.x. This affects the function setPath of the component HTML Document Handler. Such manipulation leads to server-side request forgery.
This vulnerability is documented as CVE-2025-54370. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.