PT-2025-47210 · Unknown+1 · Onlyoffice+1

Published

2025-11-17

·

Updated

2025-11-18

·

CVE-2025-64766

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Onlyoffice versions 22.11 through 25.05 Onlyoffice versions prior to Unstable 25.11
Description Onlyoffice is a software suite providing tools for document editing, collaboration, and management. A hard-coded secret within the NixOS module for the OnlyOffice document server was used to protect its file cache. An attacker knowing an existing revision ID could potentially access a document. Obtaining an arbitrary revision ID is considered difficult in practice. The likely impact is access to known documents from users with expired access.
Recommendations Update to version 25.05 or later. Update to NixOS unstable version 25.11 or later.

Exploit

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2025-64766
GHSA-58M4-5WG3-5G5V

Affected Products

Nixos
Onlyoffice