← Back

CVE-2025-66548

nvd nist
Published: Dec 5, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Prior to 1.12.7, 1.14.4, and 1.15.1, file extension can be spoofed by using RTLO characters, tricking users into download files with a different extension than what is displayed. This vulnerability is fixed in 1.12.7, 1.14.4, and 1.15.1.

Affected (3)

Products: Nextcloud: Deck
1 product
Deck
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Nextcloud
Before 1.12.7
From 1.14.0 to 1.14.4
From 1.15.0 to 1.15.1

References (4)

Source: security-advisories@github.com
Issue Tracking
Source: security-advisories@github.com
Permissions RequiredVendor Advisory

Timeline

No history available yet.