NA
CVSSv3

CVE-2025-1080

CVSSv4: 7.2 | CVSSv3: NA | CVSSv2: NA | VMScore: 820 | EPSS: 0.00051 | KEV: Not Included
Published: 04/03/2025 Updated: 04/03/2025

Vulnerability Summary

LibreOffice URI Scheme Vulnerability Enables Arbitrary Macro Execution

A vulnerability exists in LibreOffice related to Office URI Schemes and browser integration with MS SharePoint server. The issue involves the 'vnd.libreoffice.command' scheme specific to LibreOffice. An attacker could craft a malicious link in a browser using this scheme that contains an embedded inner URL. When passed to LibreOffice, this link could potentially trigger internal macros with arbitrary arguments. The vulnerability impacts LibreOffice versions from 24.8 before 24.8.5 and from 25.2 before 25.2.1. Users of these specific LibreOffice versions should update to the latest patched release to mitigate this security risk.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

the document foundation libreoffice

Vendor Advisories

LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server An additional scheme 'vndlibreofficecommand' specific to LibreOffice was added In the affected versions of LibreOffice a link in a browser using that scheme could be constructed with an embedded inner URL that when passed to LibreOffic ...