CVE-2026-63268 PUBLISHED

LFI via calcext:data-mappings, sql provider and sdbc:flat:file:// db href

Assigner: Document Fdn.
Reserved: 16.07.2026 Published: 05.10.2026 Updated: 05.10.2026

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A link of the sql type could name a folder of local text files as a database, so opening a document could read a local text file into the sheet. In fixed versions only the csv, html and xml data providers are restored when a document is loaded.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
CVSS Score: 6.7

Product Status

Vendor The Document Foundation
Product LibreOffice
Versions Default: unknown
  • affected from 26.2 to < 26.2.5 (excl.)

Credits

  • Thomas Rinsma and Edoardo Geraci from Codean Labs reporter
  • Caolán McNamara of Collabora Productivity remediation developer

References

Problem Types

  • CWE-200 Exposure of Sensitive Information to an Unauthorized Actor CWE