{"id":"CVE-2026-45279","summary":"Nextcloud: Limited path traversal via template API if using `{lang}` in config","details":"Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.14, and 32.0.0 to before 32.0.4, if {lang} is used in the template directory config value, non-admin users can in some cases copy arbitrary files (depending on unix permissions) into their own Nextcloud directory via a path traversal. It is recommended that the Nextcloud Server is upgraded to 32.0.4, 31.0.14. It is recommended that the Nextcloud Enterprise Server is upgraded to 32.0.4, 31.0.14, 30.0.17.7, 29.0.17.12, 28.0.14.15","aliases":["GHSA-j33j-qph5-4wch"],"modified":"2026-07-15T01:49:21.919087078Z","published":"2026-06-01T16:52:18.958Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-22"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45279.json"},"references":[{"type":"WEB","url":"https://github.com/nextcloud/server/pull/57414/files"},{"type":"WEB","url":"https://hackerone.com/reports/3468140"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45279.json"},{"type":"ADVISORY","url":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-j33j-qph5-4wch"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45279"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nextcloud/server","events":[{"introduced":"051e46a7a272300cf7c90b3e330fd1501fd6a996"},{"fixed":"aec70613fe00fb9bbeec2c5e6726fc3353333ce2"},{"introduced":"5ee29decb00508122f008abacea26fb3e122b13c"},{"fixed":"9a9978c82a014ade7684367c25de9798c634bdd6"}],"database_specific":{"source":"CPE_RANGE","cpe":["cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*","cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*"],"extracted_events":[{"introduced":"31.0.0"},{"fixed":"31.0.14"},{"introduced":"32.0.0"},{"fixed":"32.0.4"}]}}],"versions":["v31.0.4","v31.0.13","v31.0.14rc1","v31.0.13rc1","v32.0.4rc1","v31.0.12","v32.0.3","v31.0.12rc3","v32.0.3rc2","v31.0.12rc2","v32.0.3rc1","v31.0.12rc1","v32.0.2","v31.0.11","v31.0.7","v31.0.11rc2","v32.0.2rc2","v31.0.11rc1","v32.0.2rc1","v32.0.1","v31.0.10","v31.0.10rc2","v32.0.1rc2","v31.0.10rc1","v32.0.1rc1","v32.0.0","v31.0.9","v31.0.6","v31.0.9rc1","v31.0.8","v31.0.8rc1","v31.0.7rc1","v31.0.6rc2","v31.0.6rc1","v31.0.5","v31.0.5rc1","v31.0.4rc1","v31.0.3","v31.0.3rc2","v31.0.3rc1","v31.0.2","v31.0.2rc1","v31.0.1","v31.0.1rc2","v31.0.1rc1","v31.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45279.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"}]}