CVE-2025-66512

medium

Description

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Server Enterprise prior to 31.0.12 and 32.0.3, a missing sanitization allowed malicious users to circumvent the content security policy when a malicious user manages to trick a user it viewing an uploaded SVG outside of the Nextcloud Servers web page.

References

https://hackerone.com/reports/3357808

https://github.com/nextcloud/viewer/pull/3023

https://github.com/nextcloud/viewer/commit/5044a27d61bc40c0f134298d36af91f865335b63

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-qcw2-p26m-9gc5

Details

Source: Mitre, NVD

Published: 2025-12-05

Updated: 2025-12-05

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 5.4

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

Severity: Medium