hacker-news · Crawled Oct 6, 2026
LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings
1 CVEs
Read original article ↗
AI Summary
A vulnerability in LibreOffice and Apache OpenOffice allows malicious spreadsheets to execute arbitrary code without macro warnings by leveraging Java-based database drivers. The attack abuses legitimate features like database ranges and JDBC drivers, automatically downloading and executing a malicious JAR file when the document is opened. While LibreOffice has patched the issue (CVE-2026-63277), Apache OpenOffice remains vulnerable (CVE-2026-59265) in all versions up to 4.1.16. Users are advised to disable Java support or avoid untrusted spreadsheets until updates are available.
AI-extracted · verify before operational use