Nextcloud Server vulnerable to XSS in SVG images when opened outside of Nextcloud
CVE-2025-66512

5.4MEDIUM

Key Information:

Vendor

Nextcloud

Vendor
CVE Published:
5 December 2025

What is CVE-2025-66512?

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Server Enterprise prior to 31.0.12 and 32.0.3, a missing sanitization allowed malicious users to circumvent the content security policy when a malicious user manages to trick a user it viewing an uploaded SVG outside of the Nextcloud Servers web page.

Affected Version(s)

security-advisories >= 32.0.0beta1, < 32.0.3 < 32.0.0beta1, 32.0.3

security-advisories < 31.0.12 < 31.0.12

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-66512 : Content Security Bypass in Nextcloud Server by Malicious SVG Interaction