Summary
The Document Foundation announced seven LibreOffice vulnerabilities on June 15, 2026 with direct Claude attribution. The affected import paths include PPT, Calc formula compilation, spreadsheet tracked changes, ODF number formatting, DXF polyline import, EMF+ gradient brush import, and OOXML text box import.
The public records rate the issues around CVSS 5.4. Bugflation groups them because the same primary advisory page, same discovery attribution, and same release wave cover the full set.
Attribution
This is a direct-attribution entry. The advisories credit Anthropic as the finder and explicitly state automated discovery using Claude. The validation and reporting credits are split between Arthur Chan of Ada Logics and Trail of Bits, which is useful corroboration that the reports passed external triage before landing in LibreOffice security releases.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.