All findings

CVE-2026-8356 + 6 more medium

Claude-credited LibreOffice June 2026 document-import cluster

The Document Foundation credits Anthropic automated discovery using Claude for seven LibreOffice memory-safety CVEs across PPT, Calc, ODF, DXF, EMF+, and OOXML import paths.

Bug class
Document parser memory-safety vulnerabilities
Affected codebase
LibreOffice
Credited system
Claude / Anthropic Research
Disclosed
June 15, 2026
Attribution
Direct source attribution
Severity
medium
Source status: The Document Foundation's security page and CVE records credit Anthropic automated discovery using Claude, with Ada Logics or Trail of Bits providing validation and triage. All seven entries are fixed in LibreOffice 26.2.3, 26.2.4, or 25.8.7 depending on the branch.

Summary

The Document Foundation announced seven LibreOffice vulnerabilities on June 15, 2026 with direct Claude attribution. The affected import paths include PPT, Calc formula compilation, spreadsheet tracked changes, ODF number formatting, DXF polyline import, EMF+ gradient brush import, and OOXML text box import.

The public records rate the issues around CVSS 5.4. Bugflation groups them because the same primary advisory page, same discovery attribution, and same release wave cover the full set.

Attribution

This is a direct-attribution entry. The advisories credit Anthropic as the finder and explicitly state automated discovery using Claude. The validation and reporting credits are split between Arthur Chan of Ada Logics and Trail of Bits, which is useful corroboration that the reports passed external triage before landing in LibreOffice security releases.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.