CVE-2025-1080

LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could be constructed with an embedded inner URL that when passed to LibreOffice could call internal macros with arbitrary arguments. This issue affects LibreOffice: from 24.8 before < 24.8.5, from 25.2 before < 25.2.1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

10 Dec 2025, 18:26

Type Values Removed Values Added
References () https://www.libreoffice.org/about-us/security/advisories/cve-2025-1080 - () https://www.libreoffice.org/about-us/security/advisories/cve-2025-1080 - Vendor Advisory
References () https://lists.debian.org/debian-lts-announce/2025/06/msg00002.html - () https://lists.debian.org/debian-lts-announce/2025/06/msg00002.html - Mailing List, Third Party Advisory
First Time Libreoffice libreoffice
Debian
Debian debian Linux
Libreoffice
CPE cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE NVD-CWE-noinfo

03 Nov 2025, 20:17

Type Values Removed Values Added
Summary
  • (es) LibreOffice admite esquemas URI de Office para permitir la integración de LibreOffice en el navegador con el servidor MS SharePoint. Se agregó un esquema adicional 'vnd.libreoffice.command' específico para LibreOffice. En las versiones afectadas de LibreOffice, se podía construir un vínculo en un navegador que usara ese esquema con una URL interna incrustada que, cuando se pasaba a LibreOffice, podía llamar a macros internas con argumentos arbitrarios. Este problema afecta a LibreOffice: desde la versión 24.8 hasta la 24.8.5, desde la versión 25.2 hasta la 25.2.1.
References
  • () https://lists.debian.org/debian-lts-announce/2025/06/msg00002.html -

04 Mar 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-04 20:15

Updated : 2025-12-10 18:26


NVD link : CVE-2025-1080

Mitre link : CVE-2025-1080

CVE.ORG link : CVE-2025-1080


JSON object : View

Products Affected

libreoffice

  • libreoffice

debian

  • debian_linux
CWE
CWE-20

Improper Input Validation

NVD-CWE-noinfo