We need v3.1.0 which [depends on poi-ooxml v5.4.0|https://central.sonatype.com/artifact/org.apache.tika/tika-parent/3.1.0] which fixes https://nvd.nist.gov/vuln/detail/CVE-2025-31672 .
This message was sent by Atlassian Jira (v9.3.0#930000-sha1:287aeb6)
If image attachments aren't displayed, see this article.