CVE-2025-66550CWE-241

Nextcloud Calendar attachments of local files are offered to downloaded

Medium · published December 5, 2025

CVSS v3.1
5.7
EPSS
0%
Percentile
27.0
In the wild
Unconfirmed
What it is

Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.17 and 5.2.4, when a malicious user creates a calendar event with a crafted attachment that links to a download link of a file on the same Nextcloud server, the file would be downloaded without the user confirming the action. This vulnerability is fixed in 4.7.17 and 5.2.4.

The record
Technical detail
CVSS v3.1
5.7 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00341 · 27.0th percentile
Weakness
CWE-241 · Improper Handling of Unexpected Data Type
Published
2025-12-05T16:56Z
EPSS history
Timeline
  • 05 DEC 16:56Z
    Nextcloud Calendar attachments of local files are offered to downloaded
    cvelistv5