PT-2025-51211 · Document Foundation · Libreoffice

Karol Mazurek

·

Published

2025-12-15

·

Updated

2025-12-15

·

CVE-2025-14714

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions LibreOffice versions prior to 25.2.4
Description An authentication bypass issue existed due to the application bundling a Python interpreter that inherited Transparency, Consent, and Control (TCC) permissions granted to the main application. Executing the bundled interpreter allowed attacker scripts to run with the application’s TCC privileges. The fix involves using parent-constraints to restrict interpreter launches to only the main application with those permissions.
Recommendations Update to LibreOffice version 25.2.4 or later.

Fix

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02196
CVE-2025-14714

Affected Products

Libreoffice