Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Oct 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
The Document Foundation
The Document Foundation libreoffice |
|
| Vendors & Products |
The Document Foundation
The Document Foundation libreoffice |
Mon, 05 Oct 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LibreOffice Calc can link a cell range to an external csv data source, and the link is saved in the document. Such a link was fetched while the document loaded, so opening a document could read a local file into the sheet, or make a request to a host of the document's choosing. In fixed versions external data links are updated under the same link update control as other links in a spreadsheet. | |
| Title | LFI and GET SSRF via calcext:data-mappings and csv provider | |
| Weaknesses | CWE-200 CWE-918 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Document Fdn.
Published:
Updated: 2026-10-05T12:42:18.571Z
Reserved: 2026-07-16T08:17:05.511Z
Link: CVE-2026-63267
Updated: 2026-10-05T12:42:13.507Z
Status : Received
Published: 2026-10-05T12:17:10.713
Modified: 2026-10-05T13:16:53.637
Link: CVE-2026-63267
No data.
OpenCVE Enrichment
Updated: 2026-10-05T13:15:07Z