CVE-2025-66553: Nextcloud Tables app allowed users to view columns metadata information of any table
Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.7 and 0.9.4, authenticated users were able to view meta data of columns in other tables of the Tables app by modifying the numeric ID in a request. This vulnerability is fixed in 0.8.7 and 0.9.4.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66553?
The CVE-2025-66553 vulnerability is categorized as a medium severity issue.
How does CVE-2025-66553 affect Nextcloud users?
CVE-2025-66553 allows authenticated users to view meta data of columns in other users' tables, posing a potential data exposure risk.
How do I fix CVE-2025-66553?
To fix CVE-2025-66553, upgrade to Nextcloud Tables version 0.8.7 or 0.9.4 or later.
Who is affected by CVE-2025-66553?
Authenticated users of Nextcloud Tables prior to versions 0.8.7 and 0.9.4 are affected by CVE-2025-66553.
What are the potential impacts of CVE-2025-66553?
CVE-2025-66553 can lead to unauthorized disclosure of sensitive table metadata between authenticated users.