MEDIUM 6.5 npm

libreoffice-convert vulnerable to path traversal / arbitrary file write

GHSA-gmxc-r82q-347r · CVE-2026-54732

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

options.fileName is used to build a filesystem path
(path.join(tempDir.name, fileName)) and the caller-supplied document buffer is
written there, but fileName is never reduced to a base name. A fileName containing
"../" escapes the temporary directory, so a caller can write arbitrary content to an
arbitrary path the process can write to (e.g. ~/.ssh/authorized_keys, an /etc/cron.d
entry, or a web root).

Patches

Version 1.8.2 uses path.basename on filename to make sure the temp directory can not be escaped.

Workarounds

Make sure you supply the filename yourself and don't have it user supplied or use path.basename on filename before using it in libreoffice-convert.

Ready to move

Start Securing

Free, no credit card | First findings in minutes