VYPR
researchPublished Oct 6, 2026· 1 source

LibreOffice and OpenOffice Flaws Allow Code Execution via Malicious Spreadsheets

Security researchers have demonstrated a proof-of-concept exploit that allows malicious spreadsheets to execute arbitrary code in LibreOffice and Apache OpenOffice when Java support is enabled, bypassing standard macro warnings.

Security researchers have uncovered a critical vulnerability affecting popular open-source office suites LibreOffice and Apache OpenOffice. The flaw allows specially crafted spreadsheets to execute arbitrary code on a user's system without triggering any security warnings, a significant departure from the standard macro security prompts.

This exploit is particularly concerning because it bypasses the built-in safeguards designed to protect users from malicious macros embedded in documents. Typically, when a document contains macros, LibreOffice and OpenOffice present a warning to the user, requiring explicit permission before any automated code can run. However, this newly demonstrated vulnerability circumvents this crucial step, enabling attackers to achieve code execution simply by having a victim open a malicious spreadsheet file.

The attack vector relies on the presence and enablement of Java support within the office suite. While many users may not have Java enabled, its inclusion in the attack chain means that any system configured with this feature is potentially vulnerable. The researchers have successfully created a proof-of-concept exploit, demonstrating the feasibility of this attack.

As of the disclosure, the vulnerability has only been shown as a proof of concept, and there are no reports of it being exploited in the wild. This early stage provides a window of opportunity for developers and users to address the threat before it can be weaponized by malicious actors.

The implications of arbitrary code execution are severe. An attacker could potentially gain full control over a victim's machine, leading to data theft, installation of further malware, ransomware attacks, or the use of the compromised system as a pivot point for further network intrusions. The lack of a warning makes it even more insidious, as users might be unaware that their system has been compromised.

While the vulnerability is dependent on Java support being enabled, it highlights a broader concern about the security of complex features within widely used software. Developers of LibreOffice and Apache OpenOffice are expected to investigate this issue and release patches to mitigate the risk. Users are advised to exercise caution when opening documents from untrusted sources and to review their security settings, particularly regarding Java integration.

This discovery underscores the ongoing need for vigilance in software security, even in open-source projects that are often perceived as more transparent. The ability to execute code without user intervention represents a significant security gap that needs prompt attention from the maintainers of these widely used office productivity tools.

Synthesized by Vypr AI