Skip to main content

Generation of Error Message Containing Sensitive Information

CVE-2025-66549

Severity Low
Score 2.4/10

Summary

Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside an end-to-end encrypted directory, the path of the file was sent to the server unencrypted, making it possible for administrators to see it in log files. This vulnerability is fixed in 3.16.5.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • REQUIRED
  • HIGH
  • LOW
  • NONE

CWE-209 - Generation of Error Message Containing Sensitive Information

The software generates an error message that includes sensitive information about its environment, users, or associated data.

References

Advisory Timeline

  • Published