Nextcloud Tables Information Disclosure Vulnerability (CVE-2025-66513) — Medium Severity

Nextcloud Tables Vulnerability Exposes Sensitive Sharing Information

A security vulnerability has been discovered in the Nextcloud Tables application that could allow unauthorized users to access sensitive information about table sharing and permissions. This flaw, identified as CVE-2025-66513, impacts certain versions of the Nextcloud Tables plugin.

CVE Details

Product: Nextcloud Tables

Published: December 05, 2025

Severity: MEDIUM

Status: Analyzed

Affected Products

The vulnerability affects Nextcloud Tables versions prior to 0.8.9, 0.9.6, and 1.0.1. The specific product is Nextcloud Tables, a plugin for Nextcloud that enables users to create custom tables with defined columns.

Current Status

The vulnerability has been analyzed, and fixes have been released in specific updated versions of the Nextcloud Tables application.

Severity Level

This vulnerability is classified as MEDIUM, with a CVSS score of 4.3. While not critical, it presents a risk of sensitive information being exposed to unauthorized individuals.

Possible Solutions

To mitigate this vulnerability, users of Nextcloud Tables are strongly advised to update to one of the following patched versions:

  • 0.8.9
  • 0.9.6
  • 1.0.1

Updating to these versions will rectify the issue where information about table sharing and user permissions was not properly restricted to privileged users.

References

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2cwj-qp49-4xfw
https://github.com/nextcloud/tables/commit/b92b9560b1e70a02b103a7aeb9e22e2ab5231873
https://github.com/nextcloud/tables/pull/2148
https://hackerone.com/reports/3334165

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.