CVE-2025-1080

L

ibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could be constructed with an embedded inner URL that when passed to LibreOffice could call internal macros with arbitrary arguments. This issue affects LibreOffice: from 24.8 before < 24.8.5, from 25.2 before < 25.2.1.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

10 Dec 2025, 18:26

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
First Time Debian
Libreoffice libreoffice
Debian debian Linux
Libreoffice
References () https://www.libreoffice.org/about-us/security/advisories/cve-2025-1080 - () https://www.libreoffice.org/about-us/security/advisories/cve-2025-1080 - Vendor Advisory
References () https://lists.debian.org/debian-lts-announce/2025/06/msg00002.html - () https://lists.debian.org/debian-lts-announce/2025/06/msg00002.html - Mailing List, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

03 Nov 2025, 20:17

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/06/msg00002.html -
Summary
  • (es) LibreOffice admite esquemas URI de Office para permitir la integración de LibreOffice en el navegador con el servidor MS SharePoint. Se agregó un esquema adicional 'vnd.libreoffice.command' específico para LibreOffice. En las versiones afectadas de LibreOffice, se podía construir un vínculo en un navegador que usara ese esquema con una URL interna incrustada que, cuando se pasaba a LibreOffice, podía llamar a macros internas con argumentos arbitrarios. Este problema afecta a LibreOffice: desde la versión 24.8 hasta la 24.8.5, desde la versión 25.2 hasta la 25.2.1.

04 Mar 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-04 20:15

Updated : 2025-12-10 18:26


NVD link : CVE-2025-1080

Mitre link : CVE-2025-1080

CVE.ORG link : CVE-2025-1080


JSON object : View

CWE
CWE-20

Improper Input Validation

NVD-CWE-noinfo