Description
LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could be constructed with an embedded inner URL that when passed to LibreOffice could call internal macros with arbitrary arguments. This issue affects LibreOffice: from 24.8 before < 24.8.5, from 25.2 before < 25.2.1.
References (2)
Core 2
Core References
Mailing List, Third Party Advisory
https://lists.debian.org/debian-lts-announce/2025/06/msg00002.html
Scores
CVSS v3
7.8
EPSS
0.0012
EPSS Percentile
30.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-20
Status
published
Products (2)
debian/debian_linux
11.0
libreoffice/libreoffice
24.8.0.0 - 24.8.5.1
Published
Mar 04, 2025
Tracked Since
Feb 18, 2026