{"id":"CVE-2025-66556","summary":"Nextcloud talk allows participants to blindly delete poll drafts of other users by ID","details":"Nextcloud talk is a video & audio conferencing app for Nextcloud. Prior to 20.1.8 and 21.1.2, a participant with chat permissions was able to delete poll drafts of other participants within the conversation based on their numeric ID. This vulnerability is fixed in 20.1.8 and 21.1.2.","aliases":["GHSA-pr9f-vqgg-m2jh"],"modified":"2026-08-12T03:51:35.903707066Z","published":"2025-12-05T17:56:44.463Z","database_specific":{"cwe_ids":["CWE-639"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66556.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://hackerone.com/reports/3247386"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66556.json"},{"type":"ADVISORY","url":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-pr9f-vqgg-m2jh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66556"},{"type":"FIX","url":"https://github.com/nextcloud/spreed/commit/bd68e80d1dea98d84c1d621c2c681238cf041725"},{"type":"FIX","url":"https://github.com/nextcloud/spreed/pull/15532"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nextcloud/spreed","events":[{"introduced":"dcaf9a31031754c936ede314072a5af0fb2bb77e"},{"fixed":"bb3c86fb5f157515a5153d8fb3d866f3ff26d324"},{"introduced":"9facfc1b779304b0a9bf4789f17680c4090ee274"},{"fixed":"f0cbee3e38b5ddd943fa9027d0bacfa4d1b05fd8"},{"fixed":"bd68e80d1dea98d84c1d621c2c681238cf041725"}],"database_specific":{"extracted_events":[{"introduced":"20.0.0"},{"fixed":"20.1.8"},{"introduced":"21.0.0"},{"fixed":"21.1.2"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:nextcloud:talk:*:*:*:*:*:*:*:*"}},{"type":"GIT","repo":"https://github.com/nextcloud/talk-android","events":[{"introduced":"faab93eba03a6e803c3a071b83321312da6b3649"},{"fixed":"fae5c7188d275c4203667f0bf0164d5b97e80a59"}],"database_specific":{"extracted_events":[{"introduced":"21.0.0"},{"fixed":"21.1.2"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:nextcloud:talk:*:*:*:*:*:*:*:*"}}],"versions":["v21.1.1","v21.1.0","v21.1.0-rc.4","v20.1.7","v21.1.0-rc.3","v21.1.0-rc.2","v21.1.0-rc.1","v20.1.6","v21.0.2","v20.1.5","v21.0.1","v21.0.0","v20.1.4","v20.1.3","v20.1.2","v20.1.1","v20.1.0","v20.1.0-rc.3","v20.1.0-rc.2","v20.1.0-rc.1","v20.0.1","v20.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66556.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"}]}