VYPR
Unrated severityNVD Advisory· Published Nov 12, 2025· Updated Nov 12, 2025

Apache OpenOffice: Remote documents loaded without prompt via "external data sources" in Calc

CVE-2025-64403

Description

Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause such links to be loaded without prompt.

This issue affects Apache OpenOffice: through 4.1.15.

Users are recommended to upgrade to version 4.1.16, which fixes the issue.

Affected products

2
  • Range: <=4.1.15
  • Apache Software Foundation/Apache OpenOfficev5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.