Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.
https://www.libreoffice.org/about-us/security/advisories/cve-2023-6186
https://www.debian.org/security/2023/dsa-5574
https://lists.debian.org/debian-lts-announce/2023/12/msg00026.html