CVE-2026-63267

unknown
Published 2026-10-05 · Modified 2026-10-05
CVSS v3
—
CVSS v4 NEW
6.7
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
VIR risk
—

Description

LibreOffice Calc can link a cell range to an external csv data source, and the link is saved in the document. Such a link was fetched while the document loaded, so opening a document could read a local file into the sheet, or make a request to a host of the document's choosing. In fixed versions external data links are updated under the same link update control as other links in a spreadsheet.

Predictions

Exploit likelihood
20%
Patch ETA
—

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2026-63267 NameCVE-2026-63267 DescriptionLFI and GET SSRF via calcext:data-mappings and csv provider SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Vulnerable and fixed packages The table below lists information on source packages. Source PackageReleaseVersionStatus libreoffice…

CVE-2026-63267

NameCVE-2026-63267
DescriptionLFI and GET SSRF via calcext:data-mappings and csv provider
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libreoffice (PTS)bookworm4:7.4.7-1+deb12u14vulnerable
bookworm (security)4:7.4.7-1+deb12u13vulnerable
trixie4:25.2.3-2+deb13u6vulnerable
trixie (security)4:25.2.3-2+deb13u7vulnerable
forky4:26.8.0.3-2fixed
sid4:26.8.1.1-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libreofficesource(unstable)4:26.2.5.2-1

Notes

https://www.libreoffice.org/security/#cve-2026-63267

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
https://www.libreoffice.org/security/#cve-2026-63267

OS impact

debian Debian Mixed 4 releases
VersionStatusFixed in
trixie Affected —
sid Fixed 4:26.2.5.2-1
forky Fixed 4:26.2.5.2-1
bookworm Affected —

References

CWEs

CWE-200 CWE-918

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.