CVE-2026-3664 | xlnt-community xlnt up to 1.6.1 Encrypted XLSX File Parser compound_document.cpp read_directory out-of-bounds (Issue 141 / ID 147)
A vulnerability classified as problematic was found in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::compound_document::read_directory of the file source/detail/cryptography/compound_document.cpp of the component Encrypted XLSX File Parser. Executing a manipulation can lead to out-of-bounds read.
This vulnerability is tracked as CVE-2026-3664. The attack is restricted to local execution. Moreover, an exploit is present.
Applying a patch is advised to resolve this issue.