{"id":"CVE-2025-66558","summary":"Nextcloud Twofactor WebAuthn app was updated based on public key","details":"Nextcloud Twofactor WebAuthn is the WebAuthn Two-Factor Provider for Nextcloud. Prior to 1.4.2 and 2.4.1, a missing ownership check allowed an attack to take-away a 2FA webauthn device when correctly guessing a 80-128 character long random string of letters, numbers and symbols. The victim would then be prompted to register a new device on the next login. The attacker can not authenticate as the victim. This vulnerability is fixed in 1.4.2 and 2.4.1.","aliases":["GHSA-fr8x-mvjg-wf9q"],"modified":"2026-08-12T03:51:41.458606611Z","published":"2025-12-05T18:00:49.792Z","database_specific":{"cwe_ids":["CWE-639"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66558.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://hackerone.com/reports/3360354"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66558.json"},{"type":"ADVISORY","url":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-fr8x-mvjg-wf9q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66558"},{"type":"FIX","url":"https://github.com/nextcloud/twofactor_webauthn/commit/5d2302166d31ee2e01b2e21556bd5372156da13d"},{"type":"FIX","url":"https://github.com/nextcloud/twofactor_webauthn/pull/881"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nextcloud/twofactor_webauthn","events":[{"introduced":"5662f4994f099e232aef152fb1ec7cedc7b431be"},{"fixed":"7da9d0691cb0392ceabcc967a7c9fc7151f1e43a"},{"introduced":"13787c7093d0aaf7c5e403b0591d61b24849a7bf"},{"fixed":"72be9ebf76478e59724580ca4336fc517202e0e1"},{"fixed":"5d2302166d31ee2e01b2e21556bd5372156da13d"}],"database_specific":{"extracted_events":[{"introduced":"1.0.0"},{"fixed":"1.4.2"},{"introduced":"2.0.0"},{"fixed":"2.4.1"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:nextcloud:two-factor_webauthn:*:*:*:*:*:*:*:*"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66558.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"}]}