Nextcloud Deck File Extension Spoofing Vulnerability (CVE-2025-66548)
Nextcloud Deck, a popular Kanban-style tool for personal and team project organization within Nextcloud, has been found to have a file extension spoofing vulnerability. This flaw could trick users into downloading and opening files that appear safe but are actually malicious.
The vulnerability works by exploiting special hidden characters, known as Right-to-Left Override (RTLO) characters, within filenames. An attacker could use these characters to make a file appear to have a harmless extension (like “.txt”) while its actual extension is something dangerous (like “.exe”). If a user is deceived into downloading and opening such a file, they could unknowingly execute harmful software.
CVE Details
- Product: Nextcloud Deck
- Published Date: December 5, 2025
- Severity: Low
- Status: Analyzed
Affected Products
The vulnerability affects Nextcloud Deck versions prior to 1.12.7, 1.14.4, and 1.15.1. Specifically, this includes:
- Nextcloud Deck versions earlier than 1.12.7
- Nextcloud Deck versions earlier than 1.14.4
- Nextcloud Deck versions earlier than 1.15.1
Current Status
This vulnerability is currently classified as “Analyzed,” meaning it has been thoroughly investigated and detailed information, including fixes, is publicly available.
Severity Level
The vulnerability is rated as “Low” severity. While it requires a user to be tricked into downloading and opening a specially crafted file, and doesn’t allow for direct remote code execution without user interaction, the potential for unexpected and harmful file execution makes it a risk that should be addressed promptly. It underscores the importance of being cautious with downloaded files, even from trusted sources.
Possible Solutions
Thankfully, a solution is available to mitigate this risk. Users of Nextcloud Deck are strongly advised to update their installations to one of the following patched versions or newer to protect against this file extension spoofing:
- Nextcloud Deck 1.12.7
- Nextcloud Deck 1.14.4
- Nextcloud Deck 1.15.1
Updating to a patched version ensures that Nextcloud Deck properly handles and displays file extensions, preventing attackers from using RTLO characters to visually deceive users.
References
https://github.com/nextcloud/deck/commit/afa95d3c507465b9d31af7c88c69b76711ef185a
https://github.com/nextcloud/deck/pull/6671
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-xjvq-xvr7-xpg6
https://hackerone.com/reports/2326618


