Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-gmxc-r82q-347r | libreoffice-convert vulnerable to path traversal / arbitrary file write |
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libreoffice-convert is a Node.js module for converting office documents to different formats. Prior to 1.8.2, index.js uses the caller-controlled options.fileName value in path.join(tempDir.name, fileName) without reducing it to a base name. A filename containing ../ can escape the temporary directory because path.basename() normalization is missing and write the supplied document buffer to an arbitrary path writable by the process, including an SSH authorized_keys file, a cron configuration, or a web root. This issue is fixed in version 1.8.2. | |
| Title | libreoffice-convert: path traversal / arbitrary file write | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-27T17:21:50.743Z
Reserved: 2026-06-15T23:07:33.232Z
Link: CVE-2026-54732
No data.
Status : Received
Published: 2026-08-27T20:17:50.143
Modified: 2026-08-27T20:17:50.143
Link: CVE-2026-54732
No data.
OpenCVE Enrichment
Updated: 2026-08-28T07:30:07Z
Github GHSA