VulnerabilityAnalyzed
CVE-2025-66515
The Nextcloud Approval app allows approval or disapproval of files in the sidebar.
LOW 2.7EPSS 0.31%
Does this matter?
Lower severity and a low EPSS score (0.31%). Track it; it rarely justifies an emergency change on its own.
Description
The Nextcloud Approval app allows approval or disapproval of files in the sidebar. Prior to 1.3.1 and 2.5.0, an authenticated user listed as a requester in a workflow can set another user’s file into the “pending approval” without access to the file by using the numeric file id. This vulnerability is fixed in 1.3.1 and 2.5.0.
- CVSS 3.1
- 2.7 LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.31% probability · 24th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- nextcloud/approval
- Source
- security-advisories@github.com
References
- https://github.com/nextcloud/approval/commit/e30b56b7832255311ac800b7875f44866e88fff4Patch
- https://github.com/nextcloud/approval/pull/334Issue Tracking
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-q26g-fmjq-x5g5Patch, Vendor Advisory
- https://hackerone.com/reports/3338748Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.