CVE-2025-66557

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Prior to 1.14.6 and 1.15.2, a bug in the permission logic allowed users with "Can share" permission to modify the permissions of other recipients. This vulnerability is fixed in 1.14.6 and 1.15.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nextcloud:deck:*:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:deck:*:*:*:*:*:*:*:*

History

09 Dec 2025, 16:46

Type Values Removed Values Added
References () https://github.com/nextcloud/deck/commit/f1da8b30a455f02373d44154da04494c949a95ae - () https://github.com/nextcloud/deck/commit/f1da8b30a455f02373d44154da04494c949a95ae - Patch
References () https://github.com/nextcloud/deck/pull/7131 - () https://github.com/nextcloud/deck/pull/7131 - Issue Tracking, Patch
References () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-wwr8-hx9g-rjvv - () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-wwr8-hx9g-rjvv - Patch, Vendor Advisory
References () https://hackerone.com/reports/3247499 - () https://hackerone.com/reports/3247499 - Issue Tracking, Vendor Advisory
First Time Nextcloud deck
Nextcloud
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:nextcloud:deck:*:*:*:*:*:*:*:*

05 Dec 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-05 18:15

Updated : 2025-12-09 16:46


NVD link : CVE-2025-66557

Mitre link : CVE-2025-66557

CVE.ORG link : CVE-2025-66557


JSON object : View

Products Affected

nextcloud

  • deck
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo