CVE-2025-47792: Nextcloud Desktop 3rdparty applications can create share links via socket API
Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty applications already installed on a user machine can create link shares for almost all data via the socket API. These shares can then be easily sent off to an external service. Nextcloud Desktop fixes the issue in version 3.15. No known workarounds are available.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47792?
CVE-2025-47792 has a moderate severity level due to its potential for unauthorized data sharing.
How do I fix CVE-2025-47792?
To fix CVE-2025-47792, upgrade your Nextcloud Desktop client to version 3.15 or later.
What components are affected by CVE-2025-47792?
CVE-2025-47792 affects the Nextcloud Desktop client prior to version 3.15.
Can CVE-2025-47792 lead to data exposure?
Yes, CVE-2025-47792 can lead to unauthorized data exposure through link shares created by third-party applications.
What versions of Nextcloud Desktop are impacted by CVE-2025-47792?
Nextcloud Desktop versions prior to 3.15 are impacted by CVE-2025-47792.