LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Scripts/python sub-directories of the LibreOffice install. Protection was added, to address CVE-2019-9852, to avoid a directory traversal attack where scripts in arbitrary locations on the file system could be executed by employing a URL encoding attack to defeat the path verification step. However this protection could be bypassed by taking advantage of a flaw in how LibreOffice assembled the final script URL location directly from components of the passed in path as opposed to solely from the sanitized output of the path verification step. This issue affects: Document Foundation LibreOffice 6.2 versions prior to 6.2.7; 6.3 versions prior to 6.3.1.
Conclusion & alert: CVE-2019-9854 is rated Moderate Risk (59.7/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.94%). Core evidence: EPSS rose +1.39% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.55% | 1.94% | +1.39% |
| 2 | 2026-06-11 | 0.38% | 0.55% | +0.17% |
| 3 | 2026-06-01 | — | 0.38% | — |
Full EPSS history (22 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.8 | 3.1 | HIGH |
|
1.8 | 5.9 | [email protected] |
| 6.8 | 2.0 | MEDIUM |
|
8.6 | 6.4 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
high | CVE-2019-9854: 1 source package rows (libreoffice); 11 state rows across 7 repos (3.17-community, 3.18-community, 3.19-community, 3.20-community, 3.21-community, 3.22-community, edge-community); fixed 7, open 4. | https://security.alpinelinux.org/vuln/CVE-2019-9854 |
debian
|
not yet assigned | CVE-2019-9854 not yet assigned priority: Debian including 1 source packages (libreoffice), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2019-9854 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2019-9854 |
suse
|
high | CVE-2019-9854 severity important: SUSE including 984 source package names (libreoffice-6.2.7.1-3.24.4, libreoffice-6.2.7.1-43.56.3, …), 1181 product×package rows across 22 product lines (SUSE Linux Enterprise Desktop 12 SP4, SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP2, … (22 product lines)): Fixed 1181. | https://www.suse.com/security/cve/CVE-2019-9854/ |
ubuntu
|
medium | CVE-2019-9854 medium priority: Ubuntu including 1 source packages (libreoffice), 5 status rows across 5 suites (bionic, disco, trusty, upstream, xenial): released 3, DNE 1, needs-triage 1. | https://ubuntu.com/security/CVE-2019-9854 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| libreoffice | libreoffice | >= 6.2.0, < 6.2.7 | cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:* |
| libreoffice | libreoffice | >= 6.3.0, < 6.3.1 | cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:* |
| canonical | ubuntu_linux | 16.04 | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* |
| canonical | ubuntu_linux | 18.04 | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* |
| canonical | ubuntu_linux | 19.04 | cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:* |
| debian | debian_linux | 8.0 | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
| debian | debian_linux | 9.0 | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
| debian | debian_linux | 10.0 | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
| fedoraproject | fedora | 29 | cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:* |
| opensuse | leap | 15.0 | cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:* |
| opensuse | leap | 15.1 | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* |
| redhat | enterprise_linux | 7.0 | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux | 8.0 | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00067.html | Third Party Advisory |
| http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00055.html | Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2019/10/msg00005.html | Third Party Advisory |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XQKKOIY2DMZCXJINOLIQXD2NWISDKK3N/ | |
| https://seclists.org/bugtraq/2019/Sep/17 | Mailing List Third Party Advisory |
| https://usn.ubuntu.com/4138-1/ | Third Party Advisory |
| https://www.debian.org/security/2019/dsa-4519 | Third Party Advisory |
| https://www.libreoffice.org/about-us/security/advisories/CVE-2019-9854/ | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=1769907 | Third Party Advisory |