Unrated severityNVD Advisory· Published Nov 12, 2025· Updated Nov 12, 2025
Apache OpenOffice: Remote documents loaded without prompt via "external data sources" in Calc
CVE-2025-64403
Description
Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause such links to be loaded without prompt.
This issue affects Apache OpenOffice: through 4.1.15.
Users are recommended to upgrade to version 4.1.16, which fixes the issue.
Affected products
2- Range: <=4.1.15
- Apache Software Foundation/Apache OpenOfficev5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- lists.apache.org/thread/t7c6jhvdb00xtgd9vvn7h5sq9f4h5trtmitrevendor-advisory
- www.openoffice.org/security/cves/CVE-2025-64403.htmlmitrevendor-advisory
News mentions
0No linked articles in our index yet.