CVE-2025-66549

EUVD-2025-201462
Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside an end-to-end encrypted directory, the path of the file was sent to the server unencrypted, making it possible for administrators to see it in log files. This vulnerability is fixed in 3.16.5.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.4 LOW
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N
GitHub_MCNA
2.4 LOW
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 7%
Affected Products (NVD)
VendorProductVersion
nextclouddesktop
3.0.0 ≤
𝑥
< 3.16.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
nextcloud-desktop
bookworm
no-dsa
bullseye
postponed
bullseye (security)
vulnerable
forky
4.0.6-1
fixed
sid
4.0.6-1
fixed
trixie
3.16.7-1~deb13u1
fixed