CVE-2025-66549

LOW

Nextcloud Desktop <3.16.5 - Info Disclosure

Title source: llm
STIX 2.1

Description

Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside an end-to-end encrypted directory, the path of the file was sent to the server unencrypted, making it possible for administrators to see it in log files. This vulnerability is fixed in 3.16.5.

Scores

CVSS v3 2.4
EPSS 0.0004
EPSS Percentile 10.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-209
Status published
Products (1)
nextcloud/desktop 3.0.0 - 3.16.5
Published Dec 05, 2025
Tracked Since Feb 18, 2026