PT-2025-48979 · Collabora+1 · Code-Server+2
Published
2025-12-03
·
Updated
2025-12-31
·
CVE-2025-66208
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Collabora Online - Built-in CODE Server versions prior to 25.04.702
Description
Collabora Online - Built-in CODE Server, which provides document editing features, contains a configuration-dependent Remote Code Execution (RCE) issue in the
richdocumentscode proxy. Nextcloud users utilizing the Collabora Online - Built-in CODE Server app may be at risk through the proxy.php file and an intermediate reverse proxy. The issue allows for OS Command Injection.Recommendations
Update to version 25.04.702 or later.
Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Code-Server
Collabora Online
Nextcloud