#VU119259 Improper Handling of Unexpected Data Type in Nextcloud Calendar - CVE-2025-66550
Published: December 8, 2025
Nextcloud Calendar
Nextcloud
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper handling of unexpected data type. A remote user can create a calendar event with a crafted attachment that links to a download link of a file on the same Nextcloud server and download the file without the user confirming the action.