{"id":"CVE-2025-66550","summary":"Nextcloud Calendar attachments of local files are offered to downloaded","details":"Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.17 and 5.2.4, when a malicious user creates a calendar event with a crafted attachment that links to a download link of a file on the same Nextcloud server, the file would be downloaded without the user confirming the action. This vulnerability is fixed in 4.7.17 and 5.2.4.","aliases":["GHSA-f29c-ppmv-8mcv"],"modified":"2026-08-12T03:51:22.661522450Z","published":"2025-12-05T16:56:44.680Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-241"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66550.json"},"references":[{"type":"WEB","url":"https://hackerone.com/reports/3112033"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66550.json"},{"type":"ADVISORY","url":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-f29c-ppmv-8mcv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66550"},{"type":"FIX","url":"https://github.com/nextcloud/calendar/commit/63a6c398db01391eb9fd5297a0d4c3d6e614f769"},{"type":"FIX","url":"https://github.com/nextcloud/calendar/pull/6971"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nextcloud/calendar","events":[{"introduced":"d840d46412d121c9ae2697efed7f1ce6dd414fc2"},{"fixed":"44423c0b8f0d903102f2bbf7a12808b8ac3da64d"},{"introduced":"31203fddf125223d25f3b8b0d520f567a998e8af"},{"fixed":"f823d93dd3ac0b759c24c769832277bf94e3081d"},{"fixed":"63a6c398db01391eb9fd5297a0d4c3d6e614f769"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:nextcloud:calendar:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.0.0"},{"fixed":"4.7.17"},{"introduced":"5.0.0"},{"fixed":"5.2.4"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66550.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N"}]}