CVE-2025-66548: Nextcloud Deck app allows to spoof file extensions by using RTLO characters
Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Prior to 1.12.7, 1.14.4, and 1.15.1, file extension can be spoofed by using RTLO characters, tricking users into download files with a different extension than what is displayed. This vulnerability is fixed in 1.12.7, 1.14.4, and 1.15.1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66548?
CVE-2025-66548 has a high severity level due to its potential to deceive users with spoofed file extensions.
How do I fix CVE-2025-66548?
To fix CVE-2025-66548, upgrade Nextcloud Deck to versions 1.12.7, 1.14.4, or 1.15.1 or later.
What systems are affected by CVE-2025-66548?
CVE-2025-66548 affects Nextcloud Deck versions prior to 1.12.7, 1.14.4, and 1.15.1.
What type of vulnerability is CVE-2025-66548?
CVE-2025-66548 is a file extension spoofing vulnerability that exploits RTLO characters.
Who is responsible for fixing CVE-2025-66548?
It is the responsibility of the users and administrators of Nextcloud Deck to apply the necessary updates to mitigate CVE-2025-66548.