CVE-2025-1080

LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could be constructed with an embedded inner URL that when passed to LibreOffice could call internal macros with arbitrary arguments. This issue affects LibreOffice: from 24.8 before < 24.8.5, from 25.2 before < 25.2.1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

10 Dec 2025, 18:26

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
First Time Debian debian Linux
Debian
Libreoffice libreoffice
Libreoffice
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*
References () https://www.libreoffice.org/about-us/security/advisories/cve-2025-1080 - () https://www.libreoffice.org/about-us/security/advisories/cve-2025-1080 - Vendor Advisory
References () https://lists.debian.org/debian-lts-announce/2025/06/msg00002.html - () https://lists.debian.org/debian-lts-announce/2025/06/msg00002.html - Mailing List, Third Party Advisory

03 Nov 2025, 20:17

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/06/msg00002.html -

Information

Published : 2025-03-04 20:15

Updated : 2025-12-10 18:26


NVD link : CVE-2025-1080

Mitre link : CVE-2025-1080

CVE.ORG link : CVE-2025-1080


JSON object : View

Products Affected

libreoffice

  • libreoffice

debian

  • debian_linux
CWE
CWE-20

Improper Input Validation

NVD-CWE-noinfo