CVE-2026-63270

NameCVE-2026-63270
DescriptionURLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-12426 did not cover every place a document can supply a URL. XForms instance data and the Calc csv and sql data providers still reached the expansion. In fixed versions these places refuse URLs with internal schemes when the URL comes from the document.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6543-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libreoffice (PTS)bookworm4:7.4.7-1+deb12u14vulnerable
bookworm (security)4:7.4.7-1+deb12u13vulnerable
trixie4:25.2.3-2+deb13u6vulnerable
trixie (security)4:25.2.3-2+deb13u8fixed
forky4:26.8.0.3-2fixed
sid4:26.8.1.1-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libreofficesourcetrixie4:25.2.3-2+deb13u8DSA-6543-1
libreofficesource(unstable)4:26.2.5.2-1

Notes

https://www.libreoffice.org/security/#cve-2026-63270

Search for package or bug name: Reporting problems