CVE-2025-66514: Nextcloud Mail stored HTML injection in subject text
Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Prior to 5.5.3, a stored HTML injection in the Mail app's message list allowed an authenticated user to inject HTML into the email subjects. Javascript was correctly blocked by the content security policy of the Nextcloud Server code.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66514?
CVE-2025-66514 is classified as a medium severity vulnerability due to the potential for stored HTML injection.
How do I fix CVE-2025-66514?
To fix CVE-2025-66514, update Nextcloud Mail to version 5.5.3 or later.
Who is affected by CVE-2025-66514?
CVE-2025-66514 affects users of Nextcloud Mail versions prior to 5.5.3.
What type of attack does CVE-2025-66514 facilitate?
CVE-2025-66514 facilitates stored HTML injection attacks, allowing authenticated users to inject HTML into email subjects.
Is JavaScript execution possible via CVE-2025-66514?
No, JavaScript execution is blocked by the content security policy, limiting the impact of CVE-2025-66514.