A Closer Look at the Nextcloud Calendar Vulnerability
Nextcloud Calendar, a popular application for managing schedules within the Nextcloud ecosystem, has a security flaw that could allow unauthorized appointment booking. While the severity is rated as low, it’s still important for users to be aware and take necessary precautions.
CVE Details
- Product: Nextcloud Calendar
- Published: December 05, 2025
- Severity: Low
- Status: Analyzed
Affected Products
The vulnerability specifically impacts versions of the Nextcloud Calendar app prior to:
- 4.7.19
- 5.5.6
- 6.0.1
Current Status
This vulnerability has been analyzed, and fixes are available in newer versions of the Nextcloud Calendar app. It is recommended to update to the patched versions as soon as possible.
Severity Level
The Common Vulnerability Scoring System (CVSS) rates this vulnerability as LOW, with a score of 3.3. This indicates a relatively minor risk, but it’s always best practice to patch known vulnerabilities.
Possible Solutions
The vulnerability is fixed in Nextcloud Calendar versions 4.7.19, 5.5.6, and 6.0.1. Users are strongly advised to update their Nextcloud Calendar app to one of these versions or a later release to protect against this issue. Regularly updating your Nextcloud instance and its applications is a key part of maintaining a secure environment.
References
https://github.com/nextcloud/calendar/commit/f41650c3681fc4a4130eb883f5c0899c011326b3
https://github.com/nextcloud/calendar/pull/7537
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-7x2j-2674-fj95
https://hackerone.com/reports/3275810


