Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. Prior to 5.5.4, 6.0.6, and 7.2.5, a malicious user was able to modify their organisation and title field to load additional CSS files. Javascript and other options were correctly blocked by the content security policy of the Nextcloud Server code. This vulnerability is fixed in 5.5.4, 6.0.6, and 7.2.5.
References
| Link | Resource |
|---|---|
| https://github.com/nextcloud/contacts/commit/d954d098978dde1f121600e8b994e02f293c68b1 | Patch |
| https://github.com/nextcloud/contacts/pull/4619 | Issue Tracking Patch |
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-9v78-cpfc-v6h2 | Patch Vendor Advisory |
| https://hackerone.com/reports/3293290 | Permissions Required Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
09 Dec 2025, 17:01
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/nextcloud/contacts/commit/d954d098978dde1f121600e8b994e02f293c68b1 - Patch | |
| References | () https://github.com/nextcloud/contacts/pull/4619 - Issue Tracking, Patch | |
| References | () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-9v78-cpfc-v6h2 - Patch, Vendor Advisory | |
| References | () https://hackerone.com/reports/3293290 - Permissions Required, Vendor Advisory | |
| First Time |
Nextcloud
Nextcloud contacts |
|
| CPE | cpe:2.3:a:nextcloud:contacts:*:*:*:*:*:*:*:* |
05 Dec 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-05 18:15
Updated : 2025-12-09 17:01
NVD link : CVE-2025-66554
Mitre link : CVE-2025-66554
CVE.ORG link : CVE-2025-66554
JSON object : View
Products Affected
nextcloud
- contacts
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
