CVE-2025-66549

EUVD-2025-201462
Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside an end-to-end encrypted directory, the path of the file was sent to the server unencrypted, making it possible for administrators to see it in log files. This vulnerability is fixed in 3.16.5.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.4 LOW
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
nextclouddesktop
3.0.0 ≤
𝑥
< 3.16.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
nextcloud-desktop
bookworm
no-dsa
bullseye
postponed
bullseye (security)
vulnerable
forky
33.0.2-1
fixed
sid
33.0.2-1
fixed
trixie
3.16.7-1~deb13u1
fixed