Impact
LibreOffice can interpret specially crafted URLs that prompt the expansion of environment variables or values from INI files. When a document containing such URLs is opened, the expansion occurs and the resolved strings are transmitted to a remote server embedded in the URL, enabling an attacker to exfiltrate sensitive configuration data. The weakness resides in insufficient validation of the URL’s format and provider name, allowing bypass of the check added for a prior advisory. This results in the leakage of private information rather than execution of malicious code.
Affected Systems
The vulnerability affects LibreOffice releases from The Document Foundation. All versions that have not yet applied the patch that correctly matches the package content provider when validating URLs are susceptible. Exact version ranges are not listed, so any unsupported or older LibreOffice installation is considered at risk.
Risk and Exploitability
The CVSS score of 6.7 indicates a moderate to high severity. No EPSS score is available, so the likelihood of exploitation in the environment is uncertain. Based on the description, the likely attack vector is the delivery of a document containing malicious links, which could occur through phishing or supply‑chain compromise. The vulnerability is not listed in CISA KEV, suggesting no confirmed widespread exploitation yet, but the nature of data exfiltration makes it a concern for confidentiality. Attackers reach the vulnerable processing code by embedding the URL in a document that an end user opens; the primary trigger is social engineering or compromised file distribution.
OpenCVE Enrichment