{"id":"CVE-2025-66557","title":"Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud","summary":"Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Prior to 1.14.6 and 1.15.2, a bug in the permission logic allowed users with \"Can share\" permissi…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","cwe":["CWE-284"],"vendor":"nextcloud","product":"deck","affected":["deck >= 1.14.0, < 1.14.6","deck >= 1.15.0, < 1.15.2"],"patched":["deck 1.15.2"],"published":"2025-12-05","updated":"2026-09-25","sourceUpdated":"2026-09-25T23:10:00.463","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-66557","references":[{"url":"https://github.com/nextcloud/deck/commit/f1da8b30a455f02373d44154da04494c949a95ae","label":"security-advisories@github.com"},{"url":"https://github.com/nextcloud/deck/pull/7131","label":"security-advisories@github.com"},{"url":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-wwr8-hx9g-rjvv","label":"security-advisories@github.com"},{"url":"https://hackerone.com/reports/3247499","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00279,"epssPercentile":0.1815,"ingestedAt":"2026-09-25T23:21:16.897Z","slug":"CVE-2025-66557","body":"## Overview\n\nNextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Prior to 1.14.6 and 1.15.2, a bug in the permission logic allowed users with \"Can share\" permission to modify the permissions of other recipients. This vulnerability is fixed in 1.14.6 and 1.15.2.\n\n## Affected\n\n- `deck >= 1.14.0, < 1.14.6`\n- `deck >= 1.15.0, < 1.15.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `deck 1.15.2`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}