Skip to content
Brief Security & Trust ·

LibreOffice and OpenOffice flaw lets spreadsheets run code unasked

LibreOffice has a fix for the flaw, but Apache OpenOffice does not yet.

In brief
  • A crafted spreadsheet can run attacker code on opening, with no macro-style warning, if Java is on. LibreOffice fixed it on 5 October.
  • Apache OpenOffice is not fixed in any version up to 4.1.16. Its users can turn off Java in the settings.

The Hacker News reported on 6 October that a booby-trapped spreadsheet can run an attacker's code in LibreOffice and Apache OpenOffice. The code starts as soon as the file opens. Neither program shows the warning it gives before running a macro. LibreOffice fixed its flaw, CVE-2026-63277, in updates released on 5 October. It recommends versions 26.2.5 or 26.8.0. Apache OpenOffice tracks its flaw as CVE-2026-59265 and has not fixed it. Every version up to and including 4.1.16 is affected.

The attack works only when Java support is switched on. The Hacker News said it has so far been shown only as a proof of concept, with no reports of real attacks. The researchers' demo just opened the Calculator app, but they say the same route can run any Java code. The OpenOffice project expects a fix in version 4.1.17, which is still in testing. No release date was given. The Hacker News said it has asked The Document Foundation and the OpenOffice project for comment. Their answers are not yet known.

Teams with either office suite on staff computers can check which version they run. LibreOffice users need 26.2.5 or 26.8.0, while OpenOffice users can currently rely only on turning off Java or avoiding spreadsheets they do not trust.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: oss-security mailing list (Openwall).