Medium severity6.5GHSA Advisory· Published Aug 27, 2026· Updated Aug 27, 2026
libreoffice-convert vulnerable to path traversal / arbitrary file write
CVE-2026-54732
Description
### Impact options.fileName is used to build a filesystem path (path.join(tempDir.name, fileName)) and the caller-supplied document buffer is written there, but fileName is never reduced to a base name. A fileName containing "../" escapes the temporary directory, so a caller can write arbitrary content to an arbitrary path the process can write to (e.g. ~/.ssh/authorized_keys, an /etc/cron.d entry, or a web root).
Patches
Version 1.8.2 uses path.basename on filename to make sure the temp directory can not be escaped.
Workarounds
Make sure you supply the filename yourself and don't have it user supplied or use path.basename on filename before using it in libreoffice-convert.
Affected products
2- Range: < 1.8.2
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.