{"id":"GHSA-gmxc-r82q-347r","summary":"libreoffice-convert vulnerable to path traversal / arbitrary file write","details":"### Impact\noptions.fileName is used to build a filesystem path\n(path.join(tempDir.name, fileName)) and the caller-supplied document buffer is\nwritten there, but fileName is never reduced to a base name. A fileName containing\n\"../\" escapes the temporary directory, so a caller can write arbitrary content to an\narbitrary path the process can write to (e.g. ~/.ssh/authorized_keys, an /etc/cron.d\nentry, or a web root).\n\n### Patches\nVersion 1.8.2 uses `path.basename` on `filename` to make sure the temp directory can not be escaped.\n\n### Workarounds\nMake sure you supply the filename yourself and don't have it user supplied or use `path.basename` on `filename` before using it in `libreoffice-convert`.","aliases":["CVE-2026-54732"],"modified":"2026-08-27T17:40:40.102977Z","published":"2026-08-27T17:23:16Z","database_specific":{"cwe_ids":["CWE-22"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-08-27T17:23:16Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/elwerene/libreoffice-convert/security/advisories/GHSA-gmxc-r82q-347r"},{"type":"WEB","url":"https://github.com/elwerene/libreoffice-convert/commit/b78f17df9b9183bd503fc4635fc8b3df6705047b"},{"type":"PACKAGE","url":"https://github.com/elwerene/libreoffice-convert"}],"affected":[{"package":{"name":"libreoffice-convert","ecosystem":"npm","purl":"pkg:npm/libreoffice-convert"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.8.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-gmxc-r82q-347r/GHSA-gmxc-r82q-347r.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"}]}