๐Ÿ” CVE Alert

CVE-2026-63267

UNKNOWN 0.0

LFI and GET SSRF via calcext:data-mappings and csv provider

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

LibreOffice Calc can link a cell range to an external csv data source, and the link is saved in the document. Such a link was fetched while the document loaded, so opening a document could read a local file into the sheet, or make a request to a host of the document's choosing. In fixed versions external data links are updated under the same link update control as other links in a spreadsheet.

CWE CWE-918 CWE-200
Vendor the document foundation
Product libreoffice
Published Oct 5, 2026
Last Updated Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for the document foundation libreoffice

Be the first to know when new unknown vulnerabilities affecting the document foundation libreoffice are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

The Document Foundation / LibreOffice
26.2 < < 26.2.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
libreoffice.org: https://www.libreoffice.org/about-us/security/advisories/cve-2026-63267

Credits

๐Ÿ” Thomas Rinsma and Edoardo Geraci from Codean Labs Caolรกn McNamara of Collabora Productivity