CVE-2025-47792 MEDIUM

CVE-2025-47792: Nextcloud Desktop 3rdparty applications can create share links via socket API

Vendor Nextcloud
Product security-advisories
Weakness CWE-284
Published May 16, 2025
Last update May 16, 2025

CVSS base score

5.0/10
Attack vector Local
Attack complexity High
Privileges required Low
User interaction Required
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N

What the vulnerability does

01Description

Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty applications already installed on a user machine can create link shares for almost all data via the socket API. These shares can then be easily sent off to an external service. Nextcloud Desktop fixes the issue in version 3.15. No known workarounds are available.

Key dates

02Disclosure timeline

May 16, 2025 CVE published
May 16, 2025 Record updated