Vulnerability in Contacts App for Nextcloud Allows Malicious CSS Manipulation
CVE-2025-66554
3.5LOW
What is CVE-2025-66554?
The Contacts app for Nextcloud, which synchronizes and allows editing of contacts from various devices, is susceptible to a vulnerability that permits a malicious user to inject custom CSS files by altering their organization and title fields. This occurs before the app versions 5.5.4, 6.0.6, and 7.2.5, where the content security policy effectively blocks JavaScript and other potentially harmful options. The issue has been addressed in later versions, enhancing the security posture of the application.
Affected Version(s)
security-advisories >= 7.0.0-alpha.1, < 7.2.5 < 7.0.0-alpha.1, 7.2.5
security-advisories >= 6.0.0-alpha1, < 6.0.6 < 6.0.0-alpha1, 6.0.6
security-advisories < 5.5.4 < 5.5.4