Environment Variable Vulnerability in LibreOffice by The Document Foundation
CVE-2026-63270

6.7MEDIUM

Key Information:

Vendor
CVE Published:
5 October 2026

What is CVE-2026-63270?

An issue in LibreOffice allows the construction of malicious URLs that can expand environment variable or INI file values, posing a risk of sensitive information being sent to a remote server upon opening documents. Previous checks implemented have failed to address all instances of URL supply within documents, particularly affecting XForms data instances and Calc csv and sql data providers. The fixed versions implement strict measures to reject URLs with internal schemes originating from documents to prevent potential data leaks.

Affected Version(s)

LibreOffice 26.2

References

CVSS V4

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thomas Rinsma and Edoardo Geraci from Codean Labs
Caolán McNamara of Collabora Productivity
.