CVE-2025-66553

Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.7 and 0.9.4, authenticated users were able to view meta data of columns in other tables of the Tables app by modifying the numeric ID in a request. This vulnerability is fixed in 0.8.7 and 0.9.4.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nextcloud:tables:*:*:*:*:*:nextcloud:*:*
cpe:2.3:a:nextcloud:tables:*:*:*:*:*:nextcloud:*:*

History

09 Dec 2025, 17:03

Type Values Removed Values Added
References () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-p53h-6294-crjw - () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-p53h-6294-crjw - Patch, Vendor Advisory
References () https://github.com/nextcloud/tables/commit/e975f5bfedb6922f04cdd236cde4e26067fe064e - () https://github.com/nextcloud/tables/commit/e975f5bfedb6922f04cdd236cde4e26067fe064e - Patch
References () https://github.com/nextcloud/tables/pull/1891 - () https://github.com/nextcloud/tables/pull/1891 - Issue Tracking
References () https://hackerone.com/reports/3138721 - () https://hackerone.com/reports/3138721 - Issue Tracking, Vendor Advisory
First Time Nextcloud
Nextcloud tables
CPE cpe:2.3:a:nextcloud:tables:*:*:*:*:*:nextcloud:*:*

05 Dec 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-05 18:15

Updated : 2025-12-09 17:03


NVD link : CVE-2025-66553

Mitre link : CVE-2025-66553

CVE.ORG link : CVE-2025-66553


JSON object : View

Products Affected

nextcloud

  • tables
CWE
CWE-639

Authorization Bypass Through User-Controlled Key