CVE-2025-66512: Nextcloud Server vulnerable to XSS in SVG images when opened outside of Nextcloud
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Server Enterprise prior to 31.0.12 and 32.0.3, a missing sanitization allowed malicious users to circumvent the content security policy when a malicious user manages to trick a user it viewing an uploaded SVG outside of the Nextcloud Servers web page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66512?
CVE-2025-66512 is considered a high severity vulnerability due to its potential to allow unauthorized actions through circumvention of content security policies.
How do I fix CVE-2025-66512?
To fix CVE-2025-66512, update your Nextcloud Server to version 31.0.12 or later, or to version 32.0.3 or later.
What types of systems are affected by CVE-2025-66512?
CVE-2025-66512 affects Nextcloud Server and Server Enterprise versions prior to 31.0.12 and 32.0.3.
What are the potential risks associated with CVE-2025-66512?
The risks associated with CVE-2025-66512 include exposing users to malicious content and compromising the security of user data.
Is there any workaround for CVE-2025-66512?
There are no officially recommended workarounds for CVE-2025-66512, so upgrading to a patched version is the best course of action.