CVE-2025-66515

Source
https://cve.org/CVERecord?id=CVE-2025-66515
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66515.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-66515
Aliases
  • GHSA-q26g-fmjq-x5g5
Published
2025-12-05T17:37:06.767Z
Modified
2026-04-10T05:35:22.648774Z
Severity
  • 2.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Nextcloud Approval app allows users to request approval for other users file
Details

The Nextcloud Approval app allows approval or disapproval of files in the sidebar. Prior to 1.3.1 and 2.5.0, an authenticated user listed as a requester in a workflow can set another user’s file into the “pending approval” without access to the file by using the numeric file id. This vulnerability is fixed in 1.3.1 and 2.5.0.

Database specific
{
    "cwe_ids": [
        "CWE-287"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66515.json"
}
References

Affected packages

Git / github.com/nextcloud/approval

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/approval
Events
Database specific
{
    "versions": [
        {
            "introduced": "2.0.0"
        },
        {
            "fixed": "2.5.0"
        }
    ]
}
Type
GIT
Repo
https://github.com/nextcloud/approval
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.3.1"
        }
    ]
}

Affected versions

v0.*
v0.0.3-2-nightly
v0.0.3-3-nightly
v0.0.3-4-nightly
v0.0.3-5-nightly
v0.0.4-1-nightly
v0.0.4-2-nightly
v0.0.6
v0.0.7
v0.0.8
v0.0.9
v1.*
v1.0.0
v1.0.1
v1.0.10
v1.0.10-2-nightly
v1.0.10-3-nightly
v1.0.11
v1.0.12
v1.0.13
v1.0.14
v1.0.2
v1.0.3
v1.0.4
v1.0.4-1-nightly
v1.0.5-1-nightly
v1.0.5-2-nightly
v1.0.5-3-nightly
v1.0.5-4-nightly
v1.0.5-5-nightly
v1.0.5-6-nightly
v1.0.6
v1.0.7
v1.0.7-1-nightly
v1.0.7-2-nightly
v1.0.7-3-nightly
v1.0.7-4-nightly
v1.0.8
v1.0.8-1-nightly
v1.0.9
v1.1.0
v1.1.1
v1.2.0
v1.3.0
v2.*
v2.0.0
v2.1.0
v2.2.0
v2.3.0
v2.4.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66515.json"