Nextcloud Tables allows you to create your own tables with individual columns. Prior 0.7.6, 0.8.8, and 0.9.5, when importing a table, a user was able to specify files on the server and when their format is supported by the used PhpSpreadsheet library they would be included and their content leaked to the user. It is recommended that the Nextcloud Tables app is upgraded to 0.7.6, 0.8.8 or 0.9.5.
                
            Metrics
Affected Vendors & Products
References
        History
                    Mon, 20 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Nextcloud Nextcloud tables | |
| Vendors & Products | Nextcloud Nextcloud tables | 
Thu, 16 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Thu, 16 Oct 2025 17:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Nextcloud Tables allows you to create your own tables with individual columns. Prior 0.7.6, 0.8.8, and 0.9.5, when importing a table, a user was able to specify files on the server and when their format is supported by the used PhpSpreadsheet library they would be included and their content leaked to the user. It is recommended that the Nextcloud Tables app is upgraded to 0.7.6, 0.8.8 or 0.9.5. | |
| Title | Nextcloud Tables app allowed to include local file via PhpSpreadsheet when importing a table | |
| Weaknesses | CWE-841 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-10-16T16:48:19.618Z
Updated: 2025-10-16T18:13:19.134Z
Reserved: 2025-08-22T14:30:32.221Z
Link: CVE-2025-58051
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-10-16T18:13:14.890Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-10-16T17:15:34.417
Modified: 2025-10-21T19:31:50.020
Link: CVE-2025-58051
 Redhat
                        Redhat
                    No data.