CVE-2025-59788: XSS
Cross-site scripting (XSS) vulnerability in a reachable filespdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, and 32.0.1 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted PDF file to viewer.html. This issue is related to CVE-2024-4367, but the root cause of this Nextcloud issue is that the product exposes executable example code on a same-origin basis.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59788?
CVE-2025-59788 is classified as a cross-site scripting (XSS) vulnerability which can lead to significant security risks if exploited.
How do I fix CVE-2025-59788?
To fix CVE-2025-59788, users should upgrade Nextcloud to versions 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, or 32.0.1.
What versions of Nextcloud are affected by CVE-2025-59788?
CVE-2025-59788 affects Nextcloud versions prior to 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, and 32.0.1.
What type of attack does CVE-2025-59788 allow?
CVE-2025-59788 allows attackers to execute arbitrary JavaScript in the affected Nextcloud installations, which can lead to data theft or session hijacking.
Is there a workaround for CVE-2025-59788 if I cannot immediately upgrade?
Currently, there are no official workarounds for CVE-2025-59788, so immediate upgrading is recommended to mitigate risk.