PT-2025-47210 · Unknown+1 · Onlyoffice+1
Published
2025-11-17
·
Updated
2025-11-18
·
CVE-2025-64766
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Onlyoffice versions 22.11 through 25.05
Onlyoffice versions prior to Unstable 25.11
Description
Onlyoffice is a software suite providing tools for document editing, collaboration, and management. A hard-coded secret within the NixOS module for the OnlyOffice document server was used to protect its file cache. An attacker knowing an existing revision ID could potentially access a document. Obtaining an arbitrary revision ID is considered difficult in practice. The likely impact is access to known documents from users with expired access.
Recommendations
Update to version 25.05 or later.
Update to NixOS unstable version 25.11 or later.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nixos
Onlyoffice