CVE-2026-63267: CWE-918 Server-Side Request Forgery (SSRF) in The Document Foundation LibreOffice
Description
CVE-2026-63267 is a server-side request forgery (SSRF) vulnerability in LibreOffice Calc version 26.2. It allows a document with a linked external CSV data source to fetch data when the document is loaded, potentially reading local files or making network requests to arbitrary hosts. The issue is addressed in fixed versions by updating external data links under the same control as other spreadsheet links.
CVSS v4.0
Score 6.7medium
Affected software
The Document Foundation
LibreOffice
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
LibreOffice Calc version 26.2 contains a server-side request forgery vulnerability (CWE-918) where a cell range linked to an external CSV data source is fetched automatically when the document loads. This behavior allows an attacker to craft a document that causes the application to read local files or make network requests to hosts chosen by the attacker. The vulnerability is mitigated in fixed versions by controlling external data link updates under the same mechanism as other spreadsheet links, preventing automatic fetching without user consent.
Potential Impact
An attacker can exploit this vulnerability by embedding a specially crafted external CSV data link in a LibreOffice Calc document. When the document is opened, the application may fetch data from local files or arbitrary network hosts without explicit user approval, potentially leading to unauthorized data disclosure. The CVSS 4.0 score of 6.7 (medium severity) reflects the local attack vector with low complexity and partial confidentiality impact.
Mitigation Recommendations
No explicit patch or fixed version is provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should avoid opening untrusted documents containing external data links until an official fix is released. Once fixed versions are available, update LibreOffice to versions where external data links are controlled under the same update mechanism as other links in spreadsheets.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Document Fdn.
- Date Reserved
- 2026-07-16T08:17:05.511Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac38b252cdf04f656f731f6
Added to database: 10/05/2026, 11:33:57 UTC
Last enriched: 10/05/2026, 11:48:24 UTC
Last updated: 10/05/2026, 11:48:58 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.