PT-2025-49290 · Nextcloud+1 · Nextcloud Calendar+1

Published

2025-12-05

·

Updated

2026-01-29

·

CVE-2025-66550

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Calendar versions prior to 4.7.17 Nextcloud Calendar versions prior to 5.2.4
Description A malicious user could create a calendar event with a specially crafted attachment that links to a file on the same Nextcloud server. This action would result in the file being downloaded without requiring user confirmation. The issue involves the handling of attachments within calendar events. The vulnerability is triggered when an attachment contains a link to a file hosted on the same Nextcloud instance.
Recommendations Update Nextcloud Calendar to version 4.7.17 or later. Update Nextcloud Calendar to version 5.2.4 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2026-03381
CVE-2025-66550
GHSA-F29C-PPMV-8MCV

Affected Products

Nextcloud Calendar
Red Os