PT-2025-49297 · Nextcloud · Nextcloud Deck

Published

2025-12-05

·

Updated

2025-12-09

·

CVE-2025-66548

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Deck versions prior to 1.12.7 Nextcloud Deck versions prior to 1.14.4 Nextcloud Deck versions prior to 1.15.1
Description Nextcloud Deck is a kanban style organization tool for personal planning and project organization integrated with Nextcloud. Prior to versions 1.12.7, 1.14.4, and 1.15.1, a file extension can be manipulated using RTLO characters, potentially misleading users into downloading files with an unexpected extension.
Recommendations Update Nextcloud Deck to version 1.12.7 or later. Update Nextcloud Deck to version 1.14.4 or later. Update Nextcloud Deck to version 1.15.1 or later.

Exploit

Fix

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-66548
GHSA-XJVQ-XVR7-XPG6

Affected Products

Nextcloud Deck