Bug 1254558 (CVE-2025-66512) - VUL-0: CVE-2025-66512: In Nextcloud prior to 32.0.3 a missing sanitization allowed malicious users to circumvent the content security policy when a malicious user manages to trick a user it viewing an uploaded SVG outside
Summary: VUL-0: CVE-2025-66512: In Nextcloud prior to 32.0.3 a missing sanitization al...
Status: NEW
Alias: CVE-2025-66512
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 16.1
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: ---
Assignee: Eric Schirra
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/484068/
Whiteboard: CVSSv3.1:SUSE:CVE-2025-66512:5.4:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2025-12-08 10:15 UTC by SMASH SMASH
Modified: 2025-12-08 12:48 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2025-12-08 10:15:49 UTC
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Server Enterprise prior to 31.0.12 and 32.0.3, a missing sanitization allowed malicious users to circumvent the content security policy when a malicious user manages to trick a user it viewing an uploaded SVG outside of the Nextcloud Servers web page.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2025-66512
https://www.cve.org/CVERecord?id=CVE-2025-66512
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-qcw2-p26m-9gc5
https://github.com/nextcloud/viewer/commit/5044a27d61bc40c0f134298d36af91f865335b63
https://github.com/nextcloud/viewer/pull/3023
https://hackerone.com/reports/3357808
https://github.com/CVEProject/cvelistV5/blob/main//cves/2025/66xxx/CVE-2025-66512.json
Comment 1 Eric Schirra 2025-12-08 12:48:04 UTC
(In reply to SMASH SMASH from comment #0)
> ...In Nextcloud Server
> and Server Enterprise prior to 31.0.12 and 32.0.3, ...

What is this strange entry?
The latest Nextcloud version is 32.0.2.
There is no 32.0.3 at all.