# CVE-2026-84374

## Summary

- **CVE ID:** CVE-2026-84374
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-22, CWE-73
- **Published:** Sep 1, 2026
- **Last Modified:** Sep 4, 2026

## Description

Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Files\Disk::copy() method resolves the caller-controlled $destination supplied through Excel::store(), $export->store(), or storeExcel() against the process working directory with realpath() instead of the configured filesystem disk. If the path names an existing writable file, Disk::copy() opens it with fopen() in rb+ mode and uses stream_copy_to_stream(), bypassing Flysystem path confinement and allowing an attacker whose application input controls the export path to overwrite arbitrary existing files with export content. The rb+ behavior creates a non-truncating overwrite and trailing bytes when the new export is shorter, and overwriting an executable PHP file can lead to remote code execution. This issue is fixed in version 3.1.70.

## Affected Products

- SpartnerNL — Laravel-Excel (>= 3.1.8, < 3.1.70)

## References

- [CNA](https://github.com/SpartnerNL/Laravel-Excel/security/advisories/GHSA-c7r6-vx3h-w5g2)
- [CNA](https://github.com/SpartnerNL/Laravel-Excel/commit/b5cafdfcf7ec63924e83303763be8fcae340f70b)
- [CNA](https://github.com/SpartnerNL/Laravel-Excel/releases/tag/3.1.70)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.57%
- **EPSS Percentile:** 45.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._