Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-63270— Environment/ini-file leaks

Quick assessment

Affected
The Document Foundation LibreOffice
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

可构造的 URL 能够扩展环境变量或 INI 文件中的值,因此当用户打开包含此类链接的文档时,敏感信息可能会被泄露到远程服务器。为修复 CVE-2024-12426 而添加的检查并未覆盖文档提供 URL 的所有位置。XForms 实例数据以及 Calc 的 CSV 和 SQL 数据提供程序仍然会触发该值扩展。在修复版本中,当 URL 来自文档时,这些位置会拒绝使用内部方案的 URL。

CVSS 6.7 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-63270

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Environment/ini-file leaks
Source: CVE Program / CVE List V5
Vulnerability Description
URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-12426 did not cover every place a document can supply a URL. XForms instance data and the Calc csv and sql data providers still reached the expansion. In fixed versions these places refuse URLs with internal schemes when the URL comes from the document.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
The Document Foundation LibreOffice 26.2 ~ < 26.2.5 -

II. Public POCs for CVE-2026-63270

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-63270

请登录查看更多情报信息。

Other References for CVE-2026-63270 (1)

Same Patch Batch · The Document Foundation · 2026-10-05 · 6 CVEs total

CVE-2026-63277 8.5 HIGH RCE via calcext:data-mappings, sql provider and jdbc connector
CVE-2026-63266 6.8 MEDIUM Arbitrary file write via calcext:data-mappings, sql provider and Firebird backup functiona
CVE-2026-63269 6.7 MEDIUM LFI and GET SSRF via GStreamer and HLS playlists
CVE-2026-63267 6.7 MEDIUM LFI and GET SSRF via calcext:data-mappings and csv provider
CVE-2026-63268 6.7 MEDIUM LFI via calcext:data-mappings, sql provider and sdbc:flat:file:// db href

IV. Related Vulnerabilities

V. Comments for CVE-2026-63270

No comments yet


Leave a comment