LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings
A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown.

A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown.
There is no warning first, of the kind either program shows before it runs a macro.
The attack works only when the program's Java support is enabled.
So far, it has only been shown as a proof of concept, and there are no reports of its use in real attacks.
LibreOffice has already fixed the flaw , which it tracks as CVE-2026-63277, in updates released on October 5.
The flaw in LibreOffice was reported independently by Rick de Jager of the V12 security team and by Thomas Rinsma and Edoardo Geraci of Codean Labs.
Every version up to and including its current release, 4.1.16, is affected, and the project says a fix is expected in version 4.1.17, which is still being tested.
Until then, Apache OpenOffice users can block the attack by turning off Java in the program's settings, or by not opening spreadsheets they do not trust.
A LibreOffice or Apache OpenOffice Calc spreadsheet can hold a , a block of cells that pulls in data from an outside source and refreshes it by itself.
That outside source can be a separate database file, called an ODB, named by a web address written into the spreadsheet.
Apache OpenOffice has not fixed the matching flaw, which it tracks as CVE-2026-59265.
The ODB can name a Java database driver, known as a JDBC driver, and point to where the driver's code lives, which can be a JAR file, a bundle of Java code, or on a remote server.
The security problem, the researchers say, is that together they reach code execution without ever asking the user to trust the document, the way the program asks before it runs a macro.
The V12 team has published a proof of concept for both programs, and Caolán McNamara of Collabora Productivity wrote the fix for LibreOffice.
What happened
A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown.
There is no warning first, of the kind either program shows before it runs a macro.
The attack works only when the program's Java support is enabled.
What changed
So far, it has only been shown as a proof of concept, and there are no reports of its use in real attacks.
LibreOffice has already fixed the flaw , which it tracks as CVE-2026-63277, in updates released on October 5.
The flaw in LibreOffice was reported independently by Rick de Jager of the V12 security team and by Thomas Rinsma and Edoardo Geraci of Codean Labs.
Who is affected
Every version up to and including its current release, 4.1.16, is affected, and the project says a fix is expected in version 4.1.17, which is still being tested.
Until then, Apache OpenOffice users can block the attack by turning off Java in the program's settings, or by not opening spreadsheets they do not trust.
Why it matters
A LibreOffice or Apache OpenOffice Calc spreadsheet can hold a , a block of cells that pulls in data from an outside source and refreshes it by itself.
That outside source can be a separate database file, called an ODB, named by a web address written into the spreadsheet.
Technical details
Apache OpenOffice has not fixed the matching flaw, which it tracks as CVE-2026-59265.
The ODB can name a Java database driver, known as a JDBC driver, and point to where the driver's code lives, which can be a JAR file, a bundle of Java code, or on a remote server.
The security problem, the researchers say, is that together they reach code execution without ever asking the user to trust the document, the way the program asks before it runs a macro.
Response
The V12 team has published a proof of concept for both programs, and Caolán McNamara of Collabora Productivity wrote the fix for LibreOffice.
The Hacker News has contacted The Document Foundation, which develops LibreOffice, and the Apache OpenOffice project for comment.
What security teams should do
The attack combines features that each work as intended on their own.
When the spreadsheet is opened, the range refreshes and the program downloads the ODB from that web address.
Attribution
The Hacker News: A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown.
What to watch next
Watch for revised vendor guidance, fixed versions and mitigation updates.