CVE-2026-63269: LFI and GET SSRF via GStreamer and HLS playlists
LibreOffice can link to audio and video files from a document, and on Linux it plays them with GStreamer. A linked media file could be an HLS playlist that made GStreamer read the local files and remote URLs it listed while the document loaded, and their contents could end up in the document. In fixed versions LibreOffice does not follow playlists that name further resources, and linked media is under link update control.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this behavior?
The described behavior applies to LibreOffice on Linux when it plays linked audio or video using GStreamer. A document must contain linked media for the issue to be relevant.
What does an attacker need to provide to trigger the issue?
An attacker would need a document whose linked media file is an HLS playlist. The playlist can name local files and remote URLs that GStreamer reads while the document loads.
What is the impact of a malicious playlist?
GStreamer may read the local files and remote URLs listed by the playlist, and their contents can end up in the document. This can expose local information and cause requests to remote resources.
What changes in fixed versions?
Fixed LibreOffice versions do not follow playlists that name additional resources. Linked media is also subject to link update control.