Vulnerability in Contacts App for Nextcloud Allows Malicious CSS Manipulation
CVE-2025-66554
What is CVE-2025-66554?
The Contacts app for Nextcloud, which synchronizes and allows editing of contacts from various devices, is susceptible to a vulnerability that permits a malicious user to inject custom CSS files by altering their organization and title fields. This occurs before the app versions 5.5.4, 6.0.6, and 7.2.5, where the content security policy effectively blocks JavaScript and other potentially harmful options. The issue has been addressed in later versions, enhancing the security posture of the application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
security-advisories >= 7.0.0-alpha.1, < 7.2.5 < 7.0.0-alpha.1, 7.2.5
security-advisories >= 6.0.0-alpha1, < 6.0.6 < 6.0.0-alpha1, 6.0.6
security-advisories < 5.5.4 < 5.5.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved