Nextcloud Calendar Unauthorized File Download Vulnerability (CVE-2025-66550) — Medium Severity

Overview

The Nextcloud Calendar app had a security flaw that could allow someone with bad intentions to force users to download files without their explicit permission. This happened if a malicious user created a calendar event with a special attachment. This attachment would link to a file already on the Nextcloud server, and instead of asking for confirmation, the file would just download automatically. This sneaky trick could put users at risk if they unknowingly downloaded something harmful.

CVE Details

Nextcloud Calendar is a popular calendar application designed for the Nextcloud platform.

  • Published: December 5, 2025
  • Severity: MEDIUM
  • Status: Analyzed

Affected Products

The vulnerability impacts Nextcloud Calendar versions prior to 4.7.17 and 5.2.4. Users running any version before these numbers should be aware of this issue.

Current Status

This vulnerability has been officially analyzed. Fixes are available to address the security risk.

Severity Level

The Common Vulnerability Scoring System (CVSS) rates this vulnerability with a score of 5.7, which is considered a MEDIUM severity. While not critical, it still presents a notable risk as it could lead to unauthorized file downloads.

Possible Solutions

The good news is that Nextcloud has already released updates to patch this vulnerability. To protect your Nextcloud Calendar installation, it is crucial to update to one of the following versions:

  • Nextcloud Calendar 4.7.17
  • Nextcloud Calendar 5.2.4

These updates introduce a confirmation dialog for attachments that link to direct downloads on the same Nextcloud server, ensuring users are prompted before any files are downloaded.

References

https://github.com/nextcloud/calendar/commit/63a6c398db01391eb9fd5297a0d4c3d6e614f769

https://github.com/nextcloud/calendar/pull/6971

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-f29c-ppmv-8mcv

https://hackerone.com/reports/3112033

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.