CVE-2025-66208

Collabora Online - Built-in CODE Server (richdocumentscode) provides a built-in server with all of the document editing features of Collabora Online. In versions prior to 25.04.702, Collabora Online has a Configuration-Dependent RCE (OS Command Injection) in richdocumentscode proxy. Users of Nextcloud with Collabora Online - Built-in CODE Server app can be vulnerable to attack via proxy.php and an intermediate reverse proxy. This vulnerability is fixed in 25.04.702.
Configurations

Configuration 1 (hide)

cpe:2.3:a:collabora:online:*:*:*:*:*:*:*:*

History

08 Dec 2025, 19:37

Type Values Removed Values Added
First Time Collabora
Collabora online
References () https://github.com/CollaboraOnline/online/security/advisories/GHSA-j3q6-q5pc-v5wf - () https://github.com/CollaboraOnline/online/security/advisories/GHSA-j3q6-q5pc-v5wf - Patch, Vendor Advisory
CPE cpe:2.3:a:collabora:online:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

03 Dec 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-03 19:15

Updated : 2025-12-08 19:37


NVD link : CVE-2025-66208

Mitre link : CVE-2025-66208

CVE.ORG link : CVE-2025-66208


JSON object : View

Products Affected

collabora

  • online
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')