Vulnerability in Nextcloud Desktop Affects User Data Sharing Capabilities
CVE-2025-47792
What is CVE-2025-47792?
Nextcloud Desktop, the synchronization client for Nextcloud, is affected by a vulnerability that allows third-party applications on a user's machine to exploit the socket API. This can lead to unauthorized creation of link shares for nearly all data stored within the Nextcloud environment. These shares can be easily transmitted to external services, posing a severe risk to user data privacy. Nextcloud has addressed this issue in version 3.15, preventing such unauthorized access. Currently, there are no known workarounds for this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
security-advisories < 3.15
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved