CVE-2025-47792 - CVE House
Back to Database
Status published Medium CVE-2025-47792

Nextcloud Desktop 3rdparty applications can create share links via socket API

Vulnerability Description

Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty applications already installed on a user machine can create link shares for almost all data via the socket API. These shares can then be easily sent off to an external service. Nextcloud Desktop fixes the issue in version 3.15. No known workarounds are available.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-47792

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

security-advisories
Vulnerable Versions:
< 3.15

Timeline

Official Publish: May 16th, 2025
Last Modified: May 16th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N

Weaknesses (CWE)