Nextcloud Tables Vulnerability Exposes Sensitive Sharing Information
A security vulnerability has been discovered in the Nextcloud Tables application that could allow unauthorized users to access sensitive information about table sharing and permissions. This flaw, identified as CVE-2025-66513, impacts certain versions of the Nextcloud Tables plugin.
CVE Details
Product: Nextcloud Tables
Published: December 05, 2025
Severity: MEDIUM
Status: Analyzed
Affected Products
The vulnerability affects Nextcloud Tables versions prior to 0.8.9, 0.9.6, and 1.0.1. The specific product is Nextcloud Tables, a plugin for Nextcloud that enables users to create custom tables with defined columns.
Current Status
The vulnerability has been analyzed, and fixes have been released in specific updated versions of the Nextcloud Tables application.
Severity Level
This vulnerability is classified as MEDIUM, with a CVSS score of 4.3. While not critical, it presents a risk of sensitive information being exposed to unauthorized individuals.
Possible Solutions
To mitigate this vulnerability, users of Nextcloud Tables are strongly advised to update to one of the following patched versions:
- 0.8.9
- 0.9.6
- 1.0.1
Updating to these versions will rectify the issue where information about table sharing and user permissions was not properly restricted to privileged users.
References
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2cwj-qp49-4xfw
https://github.com/nextcloud/tables/commit/b92b9560b1e70a02b103a7aeb9e22e2ab5231873
https://github.com/nextcloud/tables/pull/2148
https://hackerone.com/reports/3334165


