Media File Processing Vulnerability in LibreOffice by The Document Foundation
CVE-2026-63269

6.7MEDIUM

Key Information:

Vendor
CVE Published:
5 October 2026

What is CVE-2026-63269?

A vulnerability in LibreOffice allows linked audio and video files within documents to exploit GStreamer on Linux systems. This issue could lead to the unintended loading of local files and remote URLs contained in HLS playlists when a document is opened. In corrected versions of LibreOffice, measures have been implemented to prevent the following of playlists that reference additional resources. Additionally, it now restricts access to linked media, ensuring that only authorized updates are processed upon opening documents.

Affected Version(s)

LibreOffice 26.2

References

CVSS V4

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thomas Rinsma and Edoardo Geraci from Codean Labs
Caolán McNamara of Collabora Productivity
.