Impact
Excelize, a Go library for handling Excel spreadsheets, contains a nil‑pointer dereference in the GetSlicers method. When a worksheet contains an extLst element but no drawing element, the library dereferences a nil drawing pointer, causing a panic that terminates the calling process. This is a classic null pointer dereference identified as CWE‑476, resulting in denial of service for any application that imports or processes such files.
Affected Systems
The vulnerability affects the qax-os:excelize library, specifically versions 2.9.0 through 2.11.0. No fixed version is available at the time of this review, and the issue is not listed in the CISA KEV catalog.
Risk and Exploitability
With a CVSS score of 8.7, the vulnerability is considered high severity. The EPSS score is not available, and the vulnerability is not present in the KEV list, suggesting the risk is primarily due to the lack of an immediate fix. Attackers can exploit this by crafting a malicious worksheet file that triggers GetSlicers, leading to a crash in unprotected usage contexts. The likely attack vector is local or injected input into an application that uses Excelize without additional controls.
OpenCVE Enrichment