CVE-2025-66548

LOW

Nextcloud Deck <1.12.7, 1.14.4, 1.15.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Prior to 1.12.7, 1.14.4, and 1.15.1, file extension can be spoofed by using RTLO characters, tricking users into download files with a different extension than what is displayed. This vulnerability is fixed in 1.12.7, 1.14.4, and 1.15.1.

Scores

CVSS v3 3.3
EPSS 0.0002
EPSS Percentile 3.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-116
Status published
Products (1)
nextcloud/deck < 1.12.7
Published Dec 05, 2025
Tracked Since Feb 18, 2026