Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.7 and 0.9.4, authenticated users were able to view meta data of columns in other tables of the Tables app by modifying the numeric ID in a request. This vulnerability is fixed in 0.8.7 and 0.9.4.
References
| Link | Resource |
|---|---|
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-p53h-6294-crjw | Patch Vendor Advisory |
| https://github.com/nextcloud/tables/commit/e975f5bfedb6922f04cdd236cde4e26067fe064e | Patch |
| https://github.com/nextcloud/tables/pull/1891 | Issue Tracking |
| https://hackerone.com/reports/3138721 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
09 Dec 2025, 17:03
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-p53h-6294-crjw - Patch, Vendor Advisory | |
| References | () https://github.com/nextcloud/tables/commit/e975f5bfedb6922f04cdd236cde4e26067fe064e - Patch | |
| References | () https://github.com/nextcloud/tables/pull/1891 - Issue Tracking | |
| References | () https://hackerone.com/reports/3138721 - Issue Tracking, Vendor Advisory | |
| First Time |
Nextcloud
Nextcloud tables |
|
| CPE | cpe:2.3:a:nextcloud:tables:*:*:*:*:*:nextcloud:*:* |
05 Dec 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-05 18:15
Updated : 2025-12-09 17:03
NVD link : CVE-2025-66553
Mitre link : CVE-2025-66553
CVE.ORG link : CVE-2025-66553
JSON object : View
Products Affected
nextcloud
- tables
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
