CVE-2026-63267 PUBLISHED

LFI and GET SSRF via calcext:data-mappings and csv provider

Assigner: Document Fdn.
Reserved: 16.07.2026 Published: 05.10.2026 Updated: 05.10.2026

LibreOffice Calc can link a cell range to an external csv data source, and the link is saved in the document. Such a link was fetched while the document loaded, so opening a document could read a local file into the sheet, or make a request to a host of the document's choosing. In fixed versions external data links are updated under the same link update control as other links in a spreadsheet.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
CVSS Score: 6.7

Product Status

Vendor The Document Foundation
Product LibreOffice
Versions Default: unknown
  • affected from 26.2 to < 26.2.5 (excl.)

Credits

  • Thomas Rinsma and Edoardo Geraci from Codean Labs reporter
  • Caolán McNamara of Collabora Productivity remediation developer

References

Problem Types

  • CWE-918 Server-Side Request Forgery (SSRF) CWE
  • CWE-200 Exposure of Sensitive Information to an Unauthorized Actor CWE

Impacts

  • CAPEC-664 Server Side Request Forgery