Environment Variable Vulnerability in LibreOffice by The Document Foundation
CVE-2026-63270
6.7MEDIUM
What is CVE-2026-63270?
An issue in LibreOffice allows the construction of malicious URLs that can expand environment variable or INI file values, posing a risk of sensitive information being sent to a remote server upon opening documents. Previous checks implemented have failed to address all instances of URL supply within documents, particularly affecting XForms data instances and Calc csv and sql data providers. The fixed versions implement strict measures to reject URLs with internal schemes originating from documents to prevent potential data leaks.
Affected Version(s)
LibreOffice 26.2
References
CVSS V4
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thomas Rinsma and Edoardo Geraci from Codean Labs
Caolán McNamara of Collabora Productivity
