Nextcloud Deck File Extension Spoofing Vulnerability (CVE-2025-66548) — Low Severity

Nextcloud Deck File Extension Spoofing Vulnerability (CVE-2025-66548)

Nextcloud Deck, a popular Kanban-style tool for personal and team project organization within Nextcloud, has been found to have a file extension spoofing vulnerability. This flaw could trick users into downloading and opening files that appear safe but are actually malicious.

The vulnerability works by exploiting special hidden characters, known as Right-to-Left Override (RTLO) characters, within filenames. An attacker could use these characters to make a file appear to have a harmless extension (like “.txt”) while its actual extension is something dangerous (like “.exe”). If a user is deceived into downloading and opening such a file, they could unknowingly execute harmful software.

CVE Details

  • Product: Nextcloud Deck
  • Published Date: December 5, 2025
  • Severity: Low
  • Status: Analyzed

Affected Products

The vulnerability affects Nextcloud Deck versions prior to 1.12.7, 1.14.4, and 1.15.1. Specifically, this includes:

  • Nextcloud Deck versions earlier than 1.12.7
  • Nextcloud Deck versions earlier than 1.14.4
  • Nextcloud Deck versions earlier than 1.15.1

Current Status

This vulnerability is currently classified as “Analyzed,” meaning it has been thoroughly investigated and detailed information, including fixes, is publicly available.

Severity Level

The vulnerability is rated as “Low” severity. While it requires a user to be tricked into downloading and opening a specially crafted file, and doesn’t allow for direct remote code execution without user interaction, the potential for unexpected and harmful file execution makes it a risk that should be addressed promptly. It underscores the importance of being cautious with downloaded files, even from trusted sources.

Possible Solutions

Thankfully, a solution is available to mitigate this risk. Users of Nextcloud Deck are strongly advised to update their installations to one of the following patched versions or newer to protect against this file extension spoofing:

  • Nextcloud Deck 1.12.7
  • Nextcloud Deck 1.14.4
  • Nextcloud Deck 1.15.1

Updating to a patched version ensures that Nextcloud Deck properly handles and displays file extensions, preventing attackers from using RTLO characters to visually deceive users.

References

https://github.com/nextcloud/deck/commit/afa95d3c507465b9d31af7c88c69b76711ef185a

https://github.com/nextcloud/deck/pull/6671

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-xjvq-xvr7-xpg6

https://hackerone.com/reports/2326618

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.