Nextcloud · Nextcloud Desktop Client · CVE-2021-22879
**Name of the Vulnerable Software and Affected Versions**
Nextcloud Desktop Client versions prior to 3.1.3
**Description**
The issue is related to resource injection due to missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.
**Recommendations**
For Nextcloud Desktop Client versions prior to 3.1.3, update to version 3.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to untrusted servers to minimize the risk of exploitation.