The Nextcloud Desktop client, designed to help users synchronize their files, recently had a privacy flaw. This issue, tracked as CVE-2025-66549, meant that when a user manually locked an end-to-end encrypted file, the file’s location was inadvertently transmitted to the server in an unencrypted format. Consequently, server administrators could potentially view these file paths in their log files, even though the file content itself remained encrypted.
CVE Details
- Product: Nextcloud Desktop
- Published: December 5, 2025
- Severity: Low
- Status: Analyzed
Affected Products
This vulnerability affects Nextcloud Desktop client versions earlier than 3.16.5. Users running any version prior to 3.16.5 are susceptible to this information disclosure issue.
Current Status
The vulnerability has been thoroughly analyzed and publicly disclosed, allowing users and administrators to take appropriate action.
Severity Level
CVE-2025-66549 is classified as a Low severity vulnerability. While the core encryption of the file content remains intact, the exposure of file paths to server administrators is a concern. For users relying on end-to-end encryption for the highest level of privacy, revealing even metadata like file locations undermines the expected confidentiality.
Possible Solutions
The good news is that a fix is available. To mitigate this vulnerability, all users of the Nextcloud Desktop client should update their software to version 3.16.5 or newer as soon as possible. This update addresses the flaw by ensuring file paths are not inadvertently logged in an unencrypted manner during the manual file locking process.
References
https://github.com/nextcloud/desktop/commit/36d6c234d42b06a6f2e9de3e413a5c3c625edad6
https://github.com/nextcloud/desktop/pull/8330
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-h9xj-qh76-q3hw
https://hackerone.com/reports/3159877


