CVE-2025-47792General(nextcloud / desktop)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty applications already installed on a user machine can create link shares for almost all data via the socket API. These shares can then be easily sent off to an external service. Nextcloud Desktop fixes the issue in version 3.15. No known workarounds are available.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • desktop

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
desktop

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-29: 104-29
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • SAAITAAMAA@saaaadhjj
    General

    this could prove useful as a persistence/backdoor mechanism. this is a variant of CVE-2025-47792. The bug was reported at @Hacker0x01 triaged and considered as my first valid finding on the platform with a pending resolution and bounty (march 17th)

    Post summary

    The post notes a variant of CVE‑2025‑47792 and hints at its potential use for persistence, but offers no concrete evidence, exploit details, or supportive technical information.

    10000642
    93 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnextclouddesktop---

Explore more