In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or world readable. This is fixed in 3.13.4.
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.
A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials.
Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of the dedicated sync directory.
A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the environment.
Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate validation due to lack of SSL certificate verification when using the "Register with a Provider" flow.
A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in for windows allowed to corrupt memory.
A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data on the login attempt.
Nextcloud Desktop discloses information when attempting to lock a file inside a end-to-end encrypted directory
Published 2025-12-05 · Analyzed
2.7EPSS 0.003
Demo
ThreatFusionAI™ Product Walkthrough
The fastest way to see what ThreatFusionAI does is to run a search. Paste any hash, IP, domain or CVE and you'll get the full report, the connected indicators and the actor attribution in one pass.
What you'll see
• Verdicts from multiple antivirus engines
• The connected IOC graph you can click through
• Ranked threat actors based on ATT&CK overlap
Next step
Start with a free search, no card needed. Check the plans if you need more volume.
ThreatFusionAI AssistantAI help & guidance
AI assistant — can make mistakes. Verify important results.