{"id":"GHSA-8jjq-8j9w-m2v6","summary":"Excelize: RIGHT() on supplementary-plane text slices with a negative index and panics","details":"`leftRight` (calc.go:14236) tests the length with `countUTF16String`, which counts a rune above U+FFFF as 2. The RIGHT branch on 14241 then slices `[]rune(text)` at `utf8.RuneCountInString(text)-numChars`, which counts it as 1. For text with N such runes the two measures are 2N and N, so any `numChars` between them passes the guard and gives a negative index. The `numChars \u003c 0` check at 14216 does not help, since the value that gets through is positive.\n\nWhat makes it worth reporting is `AutoFitColWidth`, which evaluates formulas without looking like it does, so normalising an uploaded sheet is enough to reach it. One scoping correction to my own wording there: `AutoFitColWidth` was added in v2.11.0 and does not exist at v2.10.1, so on v2.10.1 the only reachable path is an explicit `CalcCellValue`.\n\nA 6,077-byte file containing two U+1D7D9 characters in A1 and  RIGHT(A1,3)  in B1 was created and then opened in a separate program without recovery enabled:\n\n```\nv2.9.1    ok\nv2.10.0   ok\nv2.10.1   panic: slice bounds out of range [-1:]\nv2.11.0   panic: slice bounds out of range [-1:]\n```\n\nSo it is a regression, not an old defect. Commit a880146 (2026-01-16) moved the guard to `countUTF16String` and left the slice on the rune index, and `git tag --contains` gives v2.10.1 and v2.11.0 only.\n\nRIGHT only. RIGHTB reaches the same function but takes the byte branch at 14225, which is internally consistent, and I probed MID and MIDB from 1 to 5 with no panic. It is the same negative-index family as GHSA-fx5j-qcqg-grpf and GHSA-48hm-4h8j-58fg, though those are shared-string lookups in the reader rather than a unit mismatch in the formula library.","aliases":["CVE-2026-107218"],"modified":"2026-10-07T20:30:05.877569663Z","published":"2026-10-07T20:23:26Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-129"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-10-07T20:23:26Z"},"references":[{"type":"WEB","url":"https://github.com/qax-os/excelize/security/advisories/GHSA-8jjq-8j9w-m2v6"},{"type":"WEB","url":"https://github.com/qax-os/excelize/pull/2390"},{"type":"WEB","url":"https://github.com/qax-os/excelize/commit/ecd99d761fe0489f1ed308e2f7dc2e0502d1a396"},{"type":"PACKAGE","url":"https://github.com/qax-os/excelize"}],"affected":[{"package":{"name":"github.com/xuri/excelize/v2","ecosystem":"Go","purl":"pkg:golang/github.com/xuri/excelize/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.10.1"},{"fixed":"2.11.1-0.20260908032718-ecd99d761fe0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-8jjq-8j9w-m2v6/GHSA-8jjq-8j9w-m2v6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}