A medium severity vulnerability affecting libreoffice-convert versions < 1.8.2, identified as CVE-2026-54732 with a CVSS score of 6.5, affects the libreoffice-convert component's document buffer handling functionality. This flaw enables an attacker to write arbitrary content to any path the process can write to by exploiting the lack of base name reduction for the caller-supplied filename in the options.fileName field, which is then used with path.join(tempDir.name, fileName) without proper sanitization, thus allowing for path traversal and arbitrary file write attacks. This vulnerability has significant business impact as it allows attackers to potentially compromise sensitive data, such as SSH keys or web server configurations, ultimately leading to unauthorized access and potential data breaches.
We recommend you to update libreoffice-convert to version 1.8.2.[/subscribe_to_unlock_form]
A medium severity vulnerability affecting libreoffice-convert versions < 1.8.2, identified as CVE-2026-54732 with a CVSS score of 6.5, affects the libreoffice-convert component's document buffer handling functionality. This flaw enables an attacker to write arbitrary content to any path the process can write to by exploiting the lack of base name reduction for the caller-supplied filename in the options.fileName field, which is then used with path.join(tempDir.name, fileName) without proper sanitization, thus allowing for path traversal and arbitrary file write attacks. This vulnerability has significant business impact as it allows attackers to potentially compromise sensitive data, such as SSH keys or web server configurations, ultimately leading to unauthorized access and potential data breaches.
We recommend you to update libreoffice-convert to version 1.8.2.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]