CVE-2025-66549

NameCVE-2025-66549
DescriptionNextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside an end-to-end encrypted directory, the path of the file was sent to the server unencrypted, making it possible for administrators to see it in log files. This vulnerability is fixed in 3.16.5.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nextcloud-desktop (PTS)bullseye3.1.1-2+deb11u1vulnerable
bullseye (security)3.1.1-2+deb11u2vulnerable
bookworm3.7.3-1+deb12u2vulnerable
trixie3.16.7-1~deb13u1fixed
forky, sid4.0.1-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
nextcloud-desktopsource(unstable)3.16.6-3

Notes

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-h9xj-qh76-q3hw
https://github.com/nextcloud/desktop/pull/8330
Fixed by: https://github.com/nextcloud/desktop/commit/27ede927d4a86939a4243cc6a1fb656ce04512ef (v3.17.0-rc1)
Fixed by: https://github.com/nextcloud/desktop/commit/209530ae9a6dd8c6607ef4e33e84393e4ae6e3e3 (v3.16.5)

Search for package or bug name: Reporting problems