Vulnerability Description
Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.7 and 0.9.4, authenticated users were able to view meta data of columns in other tables of the Tables app by modifying the numeric ID in a request. This vulnerability is fixed in 0.8.7 and 0.9.4.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nextcloud | Tables | >= 0.8.0, < 0.8.7 |
Related Weaknesses (CWE)
References
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-p53h-6PatchVendor Advisory
- https://github.com/nextcloud/tables/commit/e975f5bfedb6922f04cdd236cde4e26067fe0Patch
- https://github.com/nextcloud/tables/pull/1891Issue Tracking
- https://hackerone.com/reports/3138721Issue TrackingVendor Advisory
FAQ
What is CVE-2025-66553?
CVE-2025-66553 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.7 and 0.9.4, authenticated users were able to view meta data of columns in other tables of the Tables app by...
How severe is CVE-2025-66553?
CVE-2025-66553 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-66553?
Check the references section above for vendor advisories and patch information. Affected products include: Nextcloud Tables.