maatwebsite/excel
HighComposerCVE-2026-84374
What to do
Update maatwebsite/excel to 3.1.70 or later.
composer require maatwebsite/excel:^3.1.70
A path traversal flaw affects the Composer package maatwebsite/excel. Affected versions: >= 3.1.8, < 3.1.70. Fixed from version 3.1.70. CVSS score 7.5.
What the flaw allows: Files outside the intended scope can be read or written.
- Package
- maatwebsite/excel
- Ecosystem
- Composer (PHP)
- Class
- Path traversal
- Affected versions
- >= 3.1.8, < 3.1.70
- CVSS
- 7.5
- Published on
- September 8, 2026
Sources
Entry built automatically from the cited security advisory, with no model rewriting. Acknowledged by the organisation or vendor, notified to an authority, or established by two independent sources.