Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside an end-to-end encrypted directory, the path of the file was sent to the server unencrypted, making it possible for administrators to see it in log files. This vulnerability is fixed in 3.16.5.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Dec 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:nextcloud:desktop:*:*:*:*:*:*:*:* |
Tue, 09 Dec 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nextcloud
Nextcloud desktop |
|
| Vendors & Products |
Nextcloud
Nextcloud desktop |
Mon, 08 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside an end-to-end encrypted directory, the path of the file was sent to the server unencrypted, making it possible for administrators to see it in log files. This vulnerability is fixed in 3.16.5. | |
| Title | Nextcloud Desktop discloses information when attempting to lock a file inside a end-to-end encrypted directory | |
| Weaknesses | CWE-209 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-12-05T17:47:00.748Z
Updated: 2025-12-08T19:54:01.534Z
Reserved: 2025-12-04T15:52:26.550Z
Link: CVE-2025-66549
Updated: 2025-12-08T19:53:53.654Z
Status : Analyzed
Published: 2025-12-05T18:15:58.133
Modified: 2025-12-09T18:58:22.650
Link: CVE-2025-66549
No data.