CVE-2025-66511

Nextcloud Calendar is a calendar app for Nextcloud. Prior to 6.0.3, the Calendar app generates participant tokens for meeting proposals using a hash function, allowing an attacker to compute valid participant tokens, which allowed them to request details and submit dates in meeting proposals. The tokens are not purely random generated. This vulnerability is fixed in 6.0.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nextcloud:calendar:*:*:*:*:*:*:*:*

History

10 Dec 2025, 16:14

Type Values Removed Values Added
First Time Nextcloud calendar
Nextcloud
CPE cpe:2.3:a:nextcloud:calendar:*:*:*:*:*:*:*:*
References () https://github.com/nextcloud/calendar/commit/8de14ae87f321f5f09280d9895a27d54d24f33fb - () https://github.com/nextcloud/calendar/commit/8de14ae87f321f5f09280d9895a27d54d24f33fb - Patch
References () https://github.com/nextcloud/calendar/pull/7659 - () https://github.com/nextcloud/calendar/pull/7659 - Issue Tracking
References () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-whm3-vv55-gf27 - () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-whm3-vv55-gf27 - Patch, Vendor Advisory
References () https://hackerone.com/reports/3385434 - () https://hackerone.com/reports/3385434 - Permissions Required, Vendor Advisory

05 Dec 2025, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-05 17:16

Updated : 2025-12-10 16:14


NVD link : CVE-2025-66511

Mitre link : CVE-2025-66511

CVE.ORG link : CVE-2025-66511


JSON object : View

Products Affected

nextcloud

  • calendar
CWE
CWE-330

Use of Insufficiently Random Values