CVE-2025-66549

Source
https://cve.org/CVERecord?id=CVE-2025-66549
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66549.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-66549
Aliases
  • GHSA-h9xj-qh76-q3hw
Downstream
Published
2025-12-05T17:47:00.748Z
Modified
2026-04-10T05:34:27.820889Z
Severity
  • 2.4 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Nextcloud Desktop discloses information when attempting to lock a file inside a end-to-end encrypted directory
Details

Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside an end-to-end encrypted directory, the path of the file was sent to the server unencrypted, making it possible for administrators to see it in log files. This vulnerability is fixed in 3.16.5.

Database specific
{
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66549.json",
    "cwe_ids": [
        "CWE-209"
    ]
}
References

Affected packages

Git / github.com/nextcloud/desktop

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/desktop
Events

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66549.json"