PT-2025-51211 · Document Foundation · Libreoffice
Karol Mazurek
·
Published
2025-12-15
·
Updated
2025-12-15
·
CVE-2025-14714
CVSS v3.1
6.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
LibreOffice versions prior to 25.2.4
Description
An authentication bypass issue existed due to the application bundling a Python interpreter that inherited Transparency, Consent, and Control (TCC) permissions granted to the main application. Executing the bundled interpreter allowed attacker scripts to run with the application’s TCC privileges. The fix involves using parent-constraints to restrict interpreter launches to only the main application with those permissions.
Recommendations
Update to LibreOffice version 25.2.4 or later.
Fix
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libreoffice