CVE-2025-66512

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Server Enterprise prior to 31.0.12 and 32.0.3, a missing sanitization allowed malicious users to circumvent the content security policy when a malicious user manages to trick a user it viewing an uploaded SVG outside of the Nextcloud Servers web page.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*

History

09 Dec 2025, 16:38

Type Values Removed Values Added
CPE cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*
CWE CWE-79
References () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-qcw2-p26m-9gc5 - () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-qcw2-p26m-9gc5 - Patch, Vendor Advisory
References () https://github.com/nextcloud/viewer/commit/5044a27d61bc40c0f134298d36af91f865335b63 - () https://github.com/nextcloud/viewer/commit/5044a27d61bc40c0f134298d36af91f865335b63 - Patch
References () https://github.com/nextcloud/viewer/pull/3023 - () https://github.com/nextcloud/viewer/pull/3023 - Issue Tracking
References () https://hackerone.com/reports/3357808 - () https://hackerone.com/reports/3357808 - Issue Tracking, Vendor Advisory
First Time Nextcloud
Nextcloud nextcloud Server

05 Dec 2025, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-05 17:16

Updated : 2025-12-09 16:38


NVD link : CVE-2025-66512

Mitre link : CVE-2025-66512

CVE.ORG link : CVE-2025-66512


JSON object : View

Products Affected

nextcloud

  • nextcloud_server
CWE
CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')