CVE-2025-66549: Nextcloud Desktop discloses information when attempting to lock a file inside a end-to-end encrypted directory
Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside an end-to-end encrypted directory, the path of the file was sent to the server unencrypted, making it possible for administrators to see it in log files. This vulnerability is fixed in 3.16.5.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66549?
CVE-2025-66549 is considered to have a medium severity rating due to the exposure of sensitive file paths in logs.
How do I fix CVE-2025-66549?
To address CVE-2025-66549, update Nextcloud Desktop to version 3.16.5 or higher.
Who is affected by CVE-2025-66549?
Users of Nextcloud Desktop versions prior to 3.16.5 are affected by CVE-2025-66549.
What is the impact of CVE-2025-66549?
The impact of CVE-2025-66549 allows administrators to access unencrypted file paths from end-to-end encrypted directories.
Is CVE-2025-66549 related to data confidentiality?
Yes, CVE-2025-66549 is related to data confidentiality as it compromises the encryption integrity by exposing file paths.