Description
The Nextcloud Desktop Client is a tool to synchronize files from a Nextcloud Server with your computer. Versions prior to 3.6.3 are missing sanitisation on qml labels which are used for basic HTML elements such as `strong`, `em` and `head` lines in the UI of the desktop client. The lack of sanitisation may allow for javascript injection. It is recommended that the Nextcloud Desktop Client is upgraded to 3.6.3. There are no known workarounds for this issue.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-64qc-vf6v-8xgg
Patch x_refsource_misc
https://github.com/nextcloud/desktop/pull/5233
Permissions Required, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/1788598
Scores
CVSS v3
5.4
EPSS
0.0167
EPSS Percentile
82.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (1)
nextcloud/desktop
< 3.6.3
Published
Feb 06, 2023
Tracked Since
Feb 18, 2026