Nextcloud Calendar is a calendar app for Nextcloud. Prior to 6.0.3, the Calendar app generates participant tokens for meeting proposals using a hash function, allowing an attacker to compute valid participant tokens, which allowed them to request details and submit dates in meeting proposals. The tokens are not purely random generated. This vulnerability is fixed in 6.0.3.
References
| Link | Resource |
|---|---|
| https://github.com/nextcloud/calendar/commit/8de14ae87f321f5f09280d9895a27d54d24f33fb | Patch |
| https://github.com/nextcloud/calendar/pull/7659 | Issue Tracking |
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-whm3-vv55-gf27 | Patch Vendor Advisory |
| https://hackerone.com/reports/3385434 | Permissions Required Vendor Advisory |
Configurations
History
10 Dec 2025, 16:14
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Nextcloud calendar
Nextcloud |
|
| CPE | cpe:2.3:a:nextcloud:calendar:*:*:*:*:*:*:*:* | |
| References | () https://github.com/nextcloud/calendar/commit/8de14ae87f321f5f09280d9895a27d54d24f33fb - Patch | |
| References | () https://github.com/nextcloud/calendar/pull/7659 - Issue Tracking | |
| References | () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-whm3-vv55-gf27 - Patch, Vendor Advisory | |
| References | () https://hackerone.com/reports/3385434 - Permissions Required, Vendor Advisory |
05 Dec 2025, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-05 17:16
Updated : 2025-12-10 16:14
NVD link : CVE-2025-66511
Mitre link : CVE-2025-66511
CVE.ORG link : CVE-2025-66511
JSON object : View
Products Affected
nextcloud
- calendar
CWE
CWE-330
Use of Insufficiently Random Values
