{"id":"CVE-2025-66512","summary":"Nextcloud Server vulnerable to XSS in SVG images when opened outside of Nextcloud","details":"Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Server Enterprise prior to 31.0.12 and 32.0.3, a missing sanitization allowed malicious users to circumvent the content security policy when a malicious user manages to trick a user it viewing an uploaded SVG outside of the Nextcloud Servers web page.","aliases":["GHSA-qcw2-p26m-9gc5"],"modified":"2026-08-12T03:51:33.257405029Z","published":"2025-12-05T16:22:50.206Z","database_specific":{"cwe_ids":["CWE-80"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66512.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://hackerone.com/reports/3357808"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66512.json"},{"type":"ADVISORY","url":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-qcw2-p26m-9gc5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66512"},{"type":"FIX","url":"https://github.com/nextcloud/viewer/commit/5044a27d61bc40c0f134298d36af91f865335b63"},{"type":"FIX","url":"https://github.com/nextcloud/viewer/pull/3023"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nextcloud/server","events":[{"introduced":"051e46a7a272300cf7c90b3e330fd1501fd6a996"},{"fixed":"6b72bb307e91390c6efe4072b2829bbd1028651c"},{"introduced":"5ee29decb00508122f008abacea26fb3e122b13c"},{"fixed":"0ff293b4efc6b3866ecdbf0d1f643738eea5db3c"}],"database_specific":{"cpe":["cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*","cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*"],"extracted_events":[{"introduced":"31.0.0"},{"fixed":"31.0.12"},{"introduced":"32.0.0"},{"fixed":"32.0.3"}],"source":"CPE_RANGE"}},{"type":"GIT","repo":"https://github.com/nextcloud/viewer","events":[{"introduced":"144669be072bd262faeec5ec9cc7f7f50059f918"},{"introduced":"0"},{"fixed":"4ae03363057e5f3149886722df2f0d84701b834c"},{"fixed":"24ca2443ce96e5e33607b936f2beac5d46096317"},{"fixed":"5044a27d61bc40c0f134298d36af91f865335b63"}],"database_specific":{"extracted_events":[{"introduced":"32.0.0beta1"},{"fixed":"32.0.3"},{"introduced":"0"},{"fixed":"31.0.12"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v31.0.4","v31.0.12rc3","v32.0.3rc2","v31.0.12rc2","v32.0.3rc1","v31.0.12rc1","v32.0.2","v31.0.11","v31.0.7","v31.0.11rc2","v32.0.2rc2","v31.0.11rc1","v32.0.2rc1","v32.0.1","v31.0.10","v31.0.10rc2","v32.0.1rc2","v31.0.10rc1","v32.0.1rc1","v32.0.0","v31.0.9","v31.0.6","v31.0.9rc1","v31.0.8","v31.0.8rc1","v31.0.7rc1","v31.0.6rc2","v31.0.6rc1","v31.0.5","v31.0.5rc1","v31.0.4rc1","v31.0.3","v31.0.3rc2","v31.0.3rc1","v31.0.2","v31.0.2rc1","v31.0.1","v31.0.1rc2","v31.0.1rc1","v31.0.0","v32.0.0rc4","v32.0.0rc3","v32.0.0rc2","v32.0.0rc1","v32.0.0beta5","v32.0.0beta4","v32.0.0beta2","v32.0.0beta3","v32.0.0beta1","v31.0.0rc5","v31.0.0rc4","v31.0.0rc3","v31.0.0rc2","v31.0.0rc1","v31.0.0beta5","v31.0.0beta4","v31.0.0beta3","v31.0.0beta2","v31.0.0beta1","v30.0.0rc1","v30.0.0beta5","v30.0.0beta4","v30.0.0beta3","v30.0.0beta2","v30.0.0beta1","v29.0.0rc1","v29.0.0beta6","v29.0.0beta5","v29.0.0beta4","v29.0.0beta3","v29.0.0beta2","v29.0.0beta1","v28.0.0beta4","v28.0.0beta3","v28.0.0beta2","v28.0.0beta1","v27.0.0rc1","v27.0.0beta2","v27.0.0beta1","v26.0.0rc1","v26.0.0beta5","v26.0.0beta3","v26.0.0beta4","v26.0.0beta2","v26.0.0beta1","v25.0.0rc1","v25.0.0beta7","v25.0.0beta6","v25.0.0beta5","v25.0.0beta4","v25.0.0beta3","v25.0.0beta2","v25.0.0beta1","v24.0.0rc3","v24.0.0rc2","v24.0.0rc1","v24.0.0beta3","v24.0.0beta2","v24.0.0beta1","v23.0.0rc3","v23.0.0rc2","v23.0.0rc1","v23.0.0","v23.0.0beta3","v23.0.0beta2","v23.0.0beta1","v22.0.0rc2","v22.0.0rc1","v22.0.0","v22.0.0beta5","v22.0.0beta4","v22.0.0beta3","v22.0.0beta2","v22.0.0beta1","v21.0.0RC1","v21.0.0beta8","v21.0.0beta7","v21.0.0beta6","v21.0.0beta5","v21.0.0beta4","v21.0.0beta3","v21.0.0beta2","v21.0.0beta1","v20.0.0RC2","v20.0.0RC1","v20.0.0","v20.0.0beta4","v20.0.0beta3","v20.0.0beta2","v20.0.0beta1","v19.0.0RC3","v19.0.0RC1","v19.0.0","v19.0.0RC2","v19.0.0beta7","v19.0.0beta6","v19.0.0beta5","v19.0.0beta4","v19.0.0beta3","v19.0.0beta2","v19.0.0beta1","v18.0.0RC2","v18.0.0RC1","v18.0.0beta4","v18.0.0beta3","v18.0.0beta2","v18.0.0beta1","v17.0.0beta4","v17.0.0beta3","v17.0.0beta2","v17.0.0beta1","v16.0.4RC1","v16.0.0RC1","v16.0.0beta3","v16.0.0beta2","v16.0.0beta1","v16.0.0alpha1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66512.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"}]}