CVE-2025-66208(collabora / online)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Collabora Online - Built-in CODE Server (richdocumentscode) provides a built-in server with all of the document editing features of Collabora Online. In versions prior to 25.04.702, Collabora Online has a Configuration-Dependent RCE (OS Command Injection) in richdocumentscode proxy. Users of Nextcloud with Collabora Online - Built-in CODE Server app can be vulnerable to attack via proxy.php and an intermediate reverse proxy. This vulnerability is fixed in 25.04.702.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • online

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
online

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-23: 109-23
Full discourse1 post
  • Thaw Tran@thaw_tran

    A Reddit homelab owner's self-hosted Nextcloud got compromised through CVE-2025-66208, a critical, unauthenticated command-injection bug in the bundled document server — reachable only because their reverse proxy trusted a header it shouldn't have. 792 upvotes, still climbing. "Self-hosted" and "safe" are two separate claims, and the second one depends on config choices most people never audit. When did you last actually check your reverse proxy config instead of assuming the defaults were fine?

    0000026
    218 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcollaboraonline---

Explore more