Skip to content

CVE-2026-63269: Verified Reproduction

CVE-2026-63269: LFI and GET SSRF via GStreamer and HLS playlists — linked media makes GStreamer read local files and fetch remote URLs on open

CVE-2026-63269 is verified against LibreOffice/core · unknown. Affected versions: LibreOffice before 26.2.5 (26.2 line) and before 26.8.0; vulnerable baseline 26.2.4.x. Fixed in 26.2.5. Vulnerability class: SSRF. This medium reproduction includes runnable sandbox proof, artifacts, and a plain-text agent view under REPRO-2026-00378.

REPRO-2026-00378 LibreOffice/core · unknown SSRF Oct 6, 2026 CVE entry .txt
Severity
MEDIUM
CVSS
6.7
Confidence
HIGH
Reproduced in
119m 41s
Tool calls
234
Spend
$8.14
01 · Overview

What Is CVE-2026-63269?

CVE-2026-63269 is a medium-severity SSRF vulnerability affecting LibreOffice/core LibreOffice before 26.2.5 (26.2 line) and before 26.8.0; vulnerable baseline 26.2.4.x. Pruva has independently reproduced it and publishes a verified, runnable proof-of-concept (reproduction REPRO-2026-00378).

02 · Severity & CVSS

CVE-2026-63269 Severity & CVSS Score

CVE-2026-63269 is rated medium severity, with a CVSS base score of 6.7 out of 10.

MEDIUM threat level
6.7 / 10 CVSS base
Weakness CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor

Medium — meaningful risk under specific conditions. Schedule a fix in the normal cycle.

03 · Affected Versions

Affected LibreOffice/core Versions

LibreOffice/core · unknown versions LibreOffice before 26.2.5 (26.2 line) and before 26.8.0; vulnerable baseline 26.2.4.x are affected.

How to Reproduce CVE-2026-63269

$ pruva-verify REPRO-2026-00378
or curl -O https://www.pruva.dev/api/v1/reproductions/REPRO-2026-00378/artifacts/bundle/repro/reproduction_steps.sh && chmod +x reproduction_steps.sh && ./reproduction_steps.sh
Run in a VM or disposable container. This exploits a real vulnerability.
06 · Proof of Reproduction

Proof of Reproduction for CVE-2026-63269

Server-side request forgery — reproduced
  • reached the target end-to-end
  • full exploit chain demonstrated
  • on the real production code path
  • high confidence
  • the upstream fix blocks the same trigger
Trigger

Crafted ODP document whose linked media (draw:plugin) URL points to an attacker-hosted HLS playlist listing a local file:// path and a remote http:// URL

Attack chain
  1. soffice open
  2. Impress media shape
  3. avmedia GStreamer playbin
  4. hlsdemux follows playlist URIs (souphttpsrc GET + filesrc local read)
How the agent worked 562 events · 234 tool calls · 2h 0m
2h 0mDuration
234Tool calls
130Reasoning steps
562Events
26Dead-ends
Agent activity over 2h 0m
Policy
1
Support
9
Repro
221
Judge
24
Variant
302
Verify
1
0:00119:30

Root Cause and Exploit Chain for CVE-2026-63269

Versions: LibreOffice < 26.2.5 / < 26.8.0 (reproduced on the

LibreOffice documents can contain linked audio/video media objects (ODF draw:plugin inside a draw:frame, e.g. an Impress MediaShape). On Linux, LibreOffice plays such media through its avmedia GStreamer backend. In vulnerable versions, merely opening a document causes LibreOffice to hand the linked media URL to GStreamer's playbin, which resolves and prerolls the stream without any user interaction or link-update consent. If the linked media is an HLS playlist (.m3u8), GStreamer's hlsdemux follows every URI listed in the playlist — including file:// URIs naming local files and http(s):// URLs naming arbitrary remote hosts — so a crafted document makes the victim's machine read local files and issue attacker-directed GET requests simply by being opened.

  • Package/component affected: LibreOffice (avmedia GStreamer backend, libavmediagst.so; document media shapes in Impress/Draw).
  • Affected versions: LibreOffice < 26.2.5 / < 26.8.0 (reproduced on the TDF 26.2.4.2 Linux x86-64 deb build).
  • Risk level and consequences: Medium (CVSS 6.7 per advisory). Remote, unauthenticated attacker delivers a document; on open, the victim's LibreOffice performs:
    • LFI: local files named in the playlist are opened and read by GStreamer (filesrc), and their contents can end up in the document (per the advisory), enabling file disclosure.
    • GET SSRF: arbitrary remote URLs listed in the playlist are fetched from the victim host (here: GStreamer souphttpsrc HTTP requests), reaching internal/loopback services.

Impact Parity

  • Disclosed/claimed maximum impact: LFI + GET SSRF via GStreamer following a document-linked HLS playlist (expected_impact=ssrf, surface viewer_document, entrypoint open_document).
  • Reproduced impact from this run: Full LFI + GET SSRF on document open through the real product (LibreOffice Impress 26.2.4.2 under Xvfb): the attacker HTTP server received the playlist GET and the SSRF segment GET from GStreamer souphttpsrc, and strace captured the soffice/GStreamer process tree opening the local secret file referenced by a file:// playlist entry. Two independent vulnerable attempts reproduced both effects; two fixed-version (26.2.5.2) attempts fetched nothing at all.
  • Parity: full
  • Not demonstrated: exfiltration of the local file's contents back to the attacker (the advisory's "contents could end up in the document" leg); the local read itself and the remote fetch are both proven.

Root Cause

LibreOffice's media shape (SdrMediaObj / avmedia::MediaWindow) creates a GStreamer playbin for the persisted linked-media URL as soon as the slide containing the media object is displayed — which happens during document load for the first page — and sets it to the paused/preroll state to render a preview frame. Prerolling an HLS playlist makes hlsdemux download the manifest and then fetch every fragment URI it lists. Neither LibreOffice nor GStreamer restricted:

  1. the scheme of fragment URIs inside a playlist served over HTTP (file:// entries are honored by filesrc), or
  2. the remote URLs a playlist can direct the player to (any http(s):// target is fetched by souphttpsrc).

Additionally, linked media was loaded automatically on document open without being subject to LibreOffice's link-update consent.

Fix (LibreOffice 26.2.5 / 26.8.0, by Caolán McNamara): per the advisory, "LibreOffice does not follow playlists that name further resources, and linked media is under link update control." In this run's negative control, the fixed 26.2.5.2 build did not even fetch the playlist when opening the same crafted document (linked media now requires link-update consent, suppressed in an unattended open), and a fortiori never followed playlist-listed resources.

Reproduction Steps

  1. bundle/repro/reproduction_steps.sh (self-contained; safe to re-run).
  2. What it does:
    • Installs runtime deps (xvfb, strace, GStreamer good/bad/libav plugins) and downloads/extracts the official TDF deb builds LibreOffice 26.2.4.2 (vulnerable) and 26.2.5.2 (fixed) into the prepared project cache.
    • Generates a valid MPEG-TS fragment (so playback genuinely proceeds through the playlist instead of erroring on undecodable bytes).
    • For each attempt (2 vulnerable + 2 fixed), it:
      • starts a local "attacker" HTTP server (python3) that logs every request and serves /stream.m3u8;
      • writes an HLS playlist listing one remote URL (http://127.0.0.1:PORT/ssrf-segment-<tag>-<n>.ts — the SSRF probe) and one local file (file://.../lfi-secret.txt — the LFI probe);
      • generates a crafted ODP whose slide 1 contains a linked media object (draw:plugin with draw:mime-type="application/vnd.sun.star.media") pointing at the playlist;
      • opens the document with the real soffice under Xvfb, tracing openat() with strace -f;
      • records playlist GETs, segment GETs, and local-file opens.
  3. Expected evidence of reproduction:
    • Vulnerable attempts: http.log shows GET /stream.m3u8 and GET /ssrf-segment-... with User-Agent GStreamer souphttpsrc; lfi-evidence.txt shows openat(... "lfi-secret.txt" ...) = <fd>.
    • Fixed attempts: neither the playlist nor the segment is fetched and the secret file is never opened.

Evidence

  • Full run log: bundle/logs/reproduction_steps.log (run 1) and bundle/logs/reproduction_steps_run2.log (run 2).
  • Per-attempt proof under bundle/repro/proof/<tag>-<n>/:
    • http.log — attacker-server request log, e.g. vulnerable-2: GET /stream.m3u8 ua=GStreamer souphttpsrc 1.28.2 libsoup/3.6.6 followed by GET /ssrf-segment-vulnerable-2.ts (same UA).
    • lfi-evidence.txt — strace excerpt, e.g. vulnerable-1: openat(AT_FDCWD, ".../proof/vulnerable-1/lfi-secret.txt", O_RDONLY) = 40.
    • stream.m3u8 — the exact playlist served; soffice.log — product stderr.
  • Machine-readable manifest with artifact hashes: bundle/repro/runtime_manifest.json.
  • Verdict: bundle/repro/validation_verdict.json.
  • Environment: Ubuntu 26.04 x86_64, LibreOffice 26.2.4.2 TDF deb (tarball sha256 810ef197…4b9900) vs LibreOffice 26.2.5.2 TDF deb (tarball sha256 2f03bfb2…1bed1e), GStreamer 1.28.2, Xvfb display, no sanitizers — real product binaries exercised through the real document-open path.

Recommendations / Next Steps

  • Upgrade to LibreOffice ≥ 26.2.5 / ≥ 26.8.0 (fixed).
  • The fix approach per the advisory: do not follow playlists that name further resources in the media backend, and put linked media behind link-update consent.
  • Testing: open a document with a linked-media HLS playlist referencing file:// and remote URLs; assert no outbound requests and no local file opens occur without explicit link-update consent.

Additional Notes

  • Idempotency: the script was run twice consecutively; both runs produced the confirmed verdict (2/2 vulnerable attempts positive, 2/2 fixed attempts negative each run). Downloads/extractions are cached in the prepared project cache and reused across runs; proof directories are regenerated per run.
  • Document format detail: the ODF media link must use draw:mime-type="application/vnd.sun.star.media"; using an HLS-specific MIME type makes the ODF importer drop the URL (verified by round-tripping through the vulnerable build itself). The structure was derived from a reference document created programmatically via UNO (com.sun.star.drawing.MediaShape.MediaURL).
  • Limitations: content exfiltration of the read file into the saved document was not needed to prove the claim ("local file reads and remote fetches") and was not attempted; the read and fetch primitives are demonstrated directly.

CVE-2026-63269 Reproduction Transcript

The agent's step-by-step process — every tool call, every handoff, the moment the exploit fired.

Full session Replay every step — scrub the timeline or play it back.

Event 1/40
0:004:22
0:00
session startedaccounts/fireworks/models/kimi-k3 · CVE-2026-63269 · REPRO-20
0:11
0:13
web search
0:14
1:40
1:40
extract_facts
no facts extracted
1:42
1:42
supportclaim_contract
1:50
1:50
1:50
1:55
1:55
2:03
2:04
2:04
2:04
3:40
3:41
$set -x; id; uname -a; command -v libreoffice soffice strace Xvfb python3 docker gst-launch-1.0 2>/dev/null; ls /pruva/project-cache/ 2>/dev/null; cat /pruva/project-cache/.pruva/cache_manifest.json 2>/dev/null; docker ps 2>&1 | head -3; df -h /workspace /tmp /pruva 2>/dev/null | head; cat /etc/os-release | head -3
0.4s✓
uid=1000(vscode) gid=1000(vscode) groups=1000(vscode)
Linux a184082c97a2 6.8.0-142-generic #142-Ubuntu SMP PREEMPT_DYNAMIC Wed Sep  2 14:24:27 UTC 2026 x86_64 GNU/Linux
repo-mirrors
{
  "schema_version": 1,
  "entries": [
    {
      "path": "repo-mirrors",
3:41
3:56
3:57
$curl -fsSL 'https://downloadarchive.documentfoundation.org/libreoffice/old/' | grep -oE 'href="26\.[0-9.]+/"' | sort -u | tail -20
0.7s✓
href="26.2.0.1/"
href="26.2.0.2/"
href="26.2.0.3/"
href="26.2.1.1/"
href="26.2.1.2/"
href="26.2.2.1/"
href="26.2.2.2/"
href="26.2.3.1/"
3:59
web search
4:06
4:08
4:12
4:13
$ls -la /pruva/project-cache/repo-mirrors/ 2>/dev/null; for d in /pruva/project-cache/repo-mirrors/*/; do echo "== $d"; git -C "$d" remote -v 2>/dev/null | head -2; done
0.4s✓
total 0
drwx------ 2 vscode vscode 40 Oct  5 20:41 .
drwx------ 4 vscode vscode 80 Oct  5 20:41 ..
== /pruva/project-cache/repo-mirrors/*/
4:22
08 · How to Fix

How to Fix CVE-2026-63269

Upgrade LibreOffice/core · unknown to 26.2.5 or later.

Coming soon

Step-by-step mitigation and hardening guidance for CVE-2026-63269 — configuration checks, workarounds where no patch exists, and how to verify you're protected — is on the way.

10 · FAQ

FAQ: CVE-2026-63269

Is CVE-2026-63269 exploitable?

Yes. Pruva independently reproduced CVE-2026-63269 in LibreOffice/core and verified the exploit fires end-to-end in a sandboxed environment. A runnable proof-of-concept script and the full agent transcript are on this page (reproduction REPRO-2026-00378).

How severe is CVE-2026-63269?

CVE-2026-63269 is rated medium severity, with a CVSS score of 6.7 out of 10.

What type of vulnerability is CVE-2026-63269?

CVE-2026-63269 is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), a SSRF vulnerability.

Which versions of LibreOffice/core are affected by CVE-2026-63269?

LibreOffice/core LibreOffice before 26.2.5 (26.2 line) and before 26.8.0; vulnerable baseline 26.2.4.x is affected by CVE-2026-63269.

Is there a fix for CVE-2026-63269?

Yes. CVE-2026-63269 is fixed in LibreOffice/core 26.2.5. Upgrading to the fixed version remediates the issue.

How can I reproduce CVE-2026-63269?

Pruva provides a verified reproduction script on this page. Download it and run it inside an isolated environment such as a container or virtual machine — never against production. The reproduction was confirmed end-to-end by Pruva's automated agents.

Is the CVE-2026-63269 reproduction verified?

Yes. Pruva reproduced CVE-2026-63269 with high confidence in a sandboxed environment, capturing the full agent transcript and artifacts as evidence.
11 · References

References for CVE-2026-63269

Authoritative sources for CVE-2026-63269 — official vulnerability databases and the upstream advisory. Pruva's reproduction verifies the issue firsthand; these are the primary records to corroborate it.