LibreOffice Vulnerability in URI Scheme Leading to Macro Execution
CVE-2025-1080
What is CVE-2025-1080?
A vulnerability in LibreOffice's handling of Office URI Schemes can allow attackers to craft a malicious link that invokes internal macros with arbitrary arguments. This issue arises when utilizing the 'vnd.libreoffice.command' scheme, which enables deeper integration with web resources like MS SharePoint servers. When a user clicks on such a link in a browser, it can execute potentially harmful macros in LibreOffice, posing significant security risks to users of the affected versions. Prompt updates to LibreOffice versions are recommended to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
LibreOffice 24.8
LibreOffice 25.2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
