Description

Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside an end-to-end encrypted directory, the path of the file was sent to the server unencrypted, making it possible for administrators to see it in log files. This vulnerability is fixed in 3.16.5.

INFO

Published Date :

2025-12-05T17:47:00.748Z

Last Modified :

2025-12-08T19:54:01.534Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2025-66549 vulnerability.

Vendors Products
Nextcloud
  • Desktop

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact