CVE-2023-39957

HIGH

Nextcloud Talk Android < 17.0.0 - Path Traversal via Unprotected Intent

Title source: llm
STIX 2.1

Description

Nextcloud Talk Android allows users to place video and audio calls through Nextcloud on Android. Prior to version 17.0.0, an unprotected intend allowed malicious third party apps to trick the Talk Android app into writing files outside of its intended cache directory. Nextcloud Talk Android version 17.0.0 has a patch for this issue. No known workarounds are available.

References (3)

Core 3
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/1997029

Scores

CVSS v3 7.8
EPSS 0.0048
EPSS Percentile 65.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (2)
nextcloud/talk 17.0.0 rc1 (3 CPE variants)
nextcloud/talk < 17.0.0
Published Aug 10, 2023
Tracked Since Feb 18, 2026