Overview
The Nextcloud Calendar app had a security flaw that could allow someone with bad intentions to force users to download files without their explicit permission. This happened if a malicious user created a calendar event with a special attachment. This attachment would link to a file already on the Nextcloud server, and instead of asking for confirmation, the file would just download automatically. This sneaky trick could put users at risk if they unknowingly downloaded something harmful.
CVE Details
Nextcloud Calendar is a popular calendar application designed for the Nextcloud platform.
- Published: December 5, 2025
- Severity: MEDIUM
- Status: Analyzed
Affected Products
The vulnerability impacts Nextcloud Calendar versions prior to 4.7.17 and 5.2.4. Users running any version before these numbers should be aware of this issue.
Current Status
This vulnerability has been officially analyzed. Fixes are available to address the security risk.
Severity Level
The Common Vulnerability Scoring System (CVSS) rates this vulnerability with a score of 5.7, which is considered a MEDIUM severity. While not critical, it still presents a notable risk as it could lead to unauthorized file downloads.
Possible Solutions
The good news is that Nextcloud has already released updates to patch this vulnerability. To protect your Nextcloud Calendar installation, it is crucial to update to one of the following versions:
- Nextcloud Calendar 4.7.17
- Nextcloud Calendar 5.2.4
These updates introduce a confirmation dialog for attachments that link to direct downloads on the same Nextcloud server, ensuring users are prompted before any files are downloaded.
References
https://github.com/nextcloud/calendar/commit/63a6c398db01391eb9fd5297a0d4c3d6e614f769
https://github.com/nextcloud/calendar/pull/6971
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-f29c-ppmv-8mcv
https://hackerone.com/reports/3112033


