Home

Description

Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.7 and 0.9.4, authenticated users were able to view meta data of columns in other tables of the Tables app by modifying the numeric ID in a request. This vulnerability is fixed in 0.8.7 and 0.9.4.

PUBLISHED Reserved 2025-12-04 | Published 2025-12-05 | Updated 2025-12-05 | Assigner GitHub_M




MEDIUM: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Problem types

CWE-639: Authorization Bypass Through User-Controlled Key

Product status

>= 0.9.0-beta.1, < 0.9.4
affected

< 0.8.7
affected

References

github.com/...sories/security/advisories/GHSA-p53h-6294-crjw

github.com/nextcloud/tables/pull/1891

github.com/...ommit/e975f5bfedb6922f04cdd236cde4e26067fe064e

hackerone.com/reports/3138721

cve.org (CVE-2025-66553)

nvd.nist.gov (CVE-2025-66553)