Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty applications already installed on a user machine can create link shares for almost all data via the socket API. These shares can then be easily sent off to an external service. Nextcloud Desktop fixes the issue in version 3.15. No known workarounds are available.
History

Fri, 16 May 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 16 May 2025 14:30:00 +0000

Type Values Removed Values Added
Description Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty applications already installed on a user machine can create link shares for almost all data via the socket API. These shares can then be easily sent off to an external service. Nextcloud Desktop fixes the issue in version 3.15. No known workarounds are available.
Title Nextcloud Desktop 3rdparty applications can create share links via socket API
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-05-16T14:13:53.209Z

Updated: 2025-05-16T14:27:53.727Z

Reserved: 2025-05-09T19:49:35.622Z

Link: CVE-2025-47792

cve-icon Vulnrichment

Updated: 2025-05-16T14:27:44.604Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-16T15:15:47.923

Modified: 2025-05-19T13:35:50.497

Link: CVE-2025-47792

cve-icon Redhat

No data.