PHPOffice/PhpSpreadsheet · error · PhpOffice\PhpSpreadsheet\Reader\Exception
Detected use of ENTITY in XML, spreadsheet file load() abort
Error message
Detected use of ENTITY in XML, spreadsheet file load() aborted to prevent XXE/XEE attacks
What it means
Error "Detected use of ENTITY in XML, spreadsheet file load() aborted to prevent XXE/XEE attacks" thrown in PHPOffice/PhpSpreadsheet.
Source
Thrown at src/PhpSpreadsheet/Reader/Security/XmlScanner.php:94
return strtoupper($matches[2]);
}
return 'UTF-8';
}
/**
* Scan the XML for use of <!ENTITY to prevent XXE/XEE attacks.
*
* @param false|string $xml
*/
public function scan($xml): string
{
// Don't rely purely on libxml_disable_entity_loader()
$pattern = '/\0*' . implode('\0*', mb_str_split($this->pattern, 1, 'UTF-8')) . '\0*/';
$xml = "$xml";
if (preg_match($pattern, $xml)) {
throw new Reader\Exception('Detected use of ENTITY in XML, spreadsheet file load() aborted to prevent XXE/XEE attacks');
}
$xml = $this->toUtf8($xml);
if (preg_match($pattern, $xml)) {
throw new Reader\Exception('Detected use of ENTITY in XML, spreadsheet file load() aborted to prevent XXE/XEE attacks');
}
if ($this->callback !== null) {
$xml = call_user_func($this->callback, $xml);
}
/** @var string $xml */
return $xml;
}
/**
* Scan the XML for use of <!ENTITY to prevent XXE/XEE attacks.
*/View on GitHub (pinned to 65b080eef4)
When it happens
Trigger: Thrown at src/PhpSpreadsheet/Reader/Security/XmlScanner.php:94 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of PHPOffice/PhpSpreadsheet@65b080eef4 (2026-08-17).
Data as JSON: /api/errors/3b51f0576fc7e74a.
Report an issue: GitHub.