{"api_version":"1","generated_at":"2026-07-24T20:52:46+00:00","cve":"CVE-2023-7101","urls":{"html":"https://cve.report/CVE-2023-7101","api":"https://cve.report/api/cve/CVE-2023-7101.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-7101","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-7101"},"summary":{"title":"Spreadsheet::ParseExcel Remote Code Execution Vulnerability","description":"Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings within the Excel parsing logic.","state":"PUBLISHED","assigner":"","published_at":"2023-12-24 22:15:00","updated_at":"2024-01-08 03:15:00"},"problem_types":[],"metrics":[],"references":[{"url":"https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2023/MNDT-2023-0019.md","name":"https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2023/MNDT-2023-0019.md","refsource":"","tags":[],"title":"","mime":"","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M2FIWDHRYTAAQLGM6AFOZVM7AFZ4H2ZR/","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M2FIWDHRYTAAQLGM6AFOZVM7AFZ4H2ZR/","refsource":"","tags":[],"title":"","mime":"","httpstatus":"200","archivestatus":"404"},{"url":"https://https://github.com/haile01/perl_spreadsheet_excel_rce_poc","name":"https://https://github.com/haile01/perl_spreadsheet_excel_rce_poc","refsource":"","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"200"},{"url":"https://https://github.com/jmcnamara/spreadsheet-parseexcel/commit/bd3159277e745468e2c553417b35d5d7dc7405bc","name":"https://https://github.com/jmcnamara/spreadsheet-parseexcel/commit/bd3159277e745468e2c553417b35d5d7dc7405bc","refsource":"","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"https://https://www.cve.org/CVERecord?id=CVE-2023-7101","name":"https://https://www.cve.org/CVERecord?id=CVE-2023-7101","refsource":"","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"https://https://metacpan.org/dist/Spreadsheet-ParseExcel","name":"https://https://metacpan.org/dist/Spreadsheet-ParseExcel","refsource":"","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2023/12/msg00025.html","name":"https://lists.debian.org/debian-lts-announce/2023/12/msg00025.html","refsource":"","tags":[],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2023/12/29/4","name":"http://www.openwall.com/lists/oss-security/2023/12/29/4","refsource":"","tags":[],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/jmcnamara/spreadsheet-parseexcel/blob/c7298592e102a375d43150cd002feed806557c15/lib/Spreadsheet/ParseExcel/Utility.pm#L171","name":"https://github.com/jmcnamara/spreadsheet-parseexcel/blob/c7298592e102a375d43150cd002feed806557c15/lib/Spreadsheet/ParseExcel/Utility.pm#L171","refsource":"","tags":[],"title":"","mime":"","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IFEHKULQRVXHIV7XXK2RGD4VQN6Y4CV5/","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IFEHKULQRVXHIV7XXK2RGD4VQN6Y4CV5/","refsource":"","tags":[],"title":"","mime":"","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-7101","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-7101","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":{"cve_year":"2023","cve_id":"7101","cve":"CVE-2023-7101","vendorProject":"Spreadsheet::ParseExcel","product":"Spreadsheet::ParseExcel","vulnerabilityName":"Spreadsheet::ParseExcel Remote Code Execution Vulnerability","dateAdded":"2024-01-02","shortDescription":"Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings within the Excel parsing logic.","requiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","dueDate":"2024-01-23","knownRansomwareCampaignUse":"Unknown","notes":"This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://metacpan.org/dist/Spreadsheet-ParseExcel and Barracuda's specific implementation and fix for their downstream issue CVE-2023-7102 at https://www.barracuda.com/company/legal/esg-vulnerability;  https://nvd.nist.gov/vuln/detail/CVE-2023-7101","cwes":"CWE-95","catalogVersion":"2026.07.24","updated_at":"2026-07-24 18:00:38"},"epss":{"cve_year":"2023","cve_id":"7101","cve":"CVE-2023-7101","epss":"0.168320000","percentile":"0.967220000","score_date":"2026-07-23","updated_at":"2026-07-24 00:10:12"},"legacy_qids":[{"cve":"CVE-2023-7101","qid":"285070","title":"Fedora Security Update for perl (FEDORA-2023-921f6975c2)"},{"cve":"CVE-2023-7101","qid":"357033","title":"Amazon Linux Security Advisory for perl-Spreadsheet-ParseExcel : ALAS2023-2024-491"},{"cve":"CVE-2023-7101","qid":"357043","title":"Amazon Linux Security Advisory for perl-Spreadsheet-ParseExcel : ALAS-2024-1905"},{"cve":"CVE-2023-7101","qid":"505789","title":"Alpine Linux Security Update for perl-spreadsheet-parseexcel"},{"cve":"CVE-2023-7101","qid":"6000414","title":"Debian Security Update for libspreadsheet-parseexcel-perl (DSA 5592-1)"},{"cve":"CVE-2023-7101","qid":"6000417","title":"Debian Security Update for libspreadsheet-parseexcel-perl (DLA 3702-1)"},{"cve":"CVE-2023-7101","qid":"691422","title":"Free Berkeley Software Distribution (FreeBSD) Security Update for p5 (cb22a9a6-c907-11ee-8d1c-40b034429ecf)"},{"cve":"CVE-2023-7101","qid":"755629","title":"SUSE Enterprise Linux Security Update for perl-Spreadsheet-ParseExcel (SUSE-SU-2024:0158-1)"}]},"source_records":{"cve_program":null,"nvd":{"publishedDate":"2023-12-24 22:15:00","lastModifiedDate":"2024-01-08 03:15:00","problem_types":[],"metrics":[],"configurations":{"CVE_data_version":"4.0","nodes":[]}},"legacy_mitre":{"record":null,"notes":[]}}}