CVE-2025-1080: Macro URL arbitrary script execution
Last updated 11 March 2025
Other sources
LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could be constructed with an embedded inner URL that when passed to LibreOffice could call internal macros with arbitrary arguments. This issue affects LibreOffice: from 24.8 before < 24.8.5, from 25.2 before < 25.2.1.
— Red Hat
LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could be constructed with an embedded inner URL that when passed to LibreOffice could call internal macros with arbitrary arguments. This issue affects LibreOffice: from 24.8 before < 24.8.5, from 25.2 before < 25.2.1.
— NVD
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1080?
CVE-2025-1080 is classified as a moderate severity vulnerability affecting specific versions of LibreOffice.
How do I fix CVE-2025-1080?
To fix CVE-2025-1080, users should update LibreOffice to the latest available version that addresses this vulnerability.
Which versions of LibreOffice are affected by CVE-2025-1080?
CVE-2025-1080 affects LibreOffice versions 24.8 to 24.8.5 and 25.2 to 25.2.1.
What specific feature in LibreOffice is related to CVE-2025-1080?
CVE-2025-1080 is related to the additional URI scheme 'vnd.libreoffice.command' that integrates LibreOffice with MS SharePoint.
What potential impact does CVE-2025-1080 have on users?
CVE-2025-1080 may allow an attacker to execute unintended commands via malicious links targeting affected versions of LibreOffice.