---
id: CVE-2025-58051
title: Nextcloud Tables allows you to create your own tables with individual columns
summary: >-
  Nextcloud Tables allows you to create your own tables with individual columns.
  Prior 0.7.6, 0.8.8, and 0.9.5, when importing a table, a user was able to
  specify files on the server and when their format is supported by the used
  PhpSpread…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-841
published: '2025-10-16'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-58051'
references:
  - url: >-
      https://github.com/nextcloud/security-advisories/security/advisories/GHSA-wpp5-4w35-pxq6
    label: security-advisories@github.com
  - url: 'https://github.com/nextcloud/tables/pull/1936'
    label: security-advisories@github.com
  - url: 'https://hackerone.com/reports/3249624'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00532
epssPercentile: 0.43156
ingestedAt: '2026-10-09T12:53:29.033Z'
---

## Overview

Nextcloud Tables allows you to create your own tables with individual columns. Prior 0.7.6, 0.8.8, and 0.9.5, when importing a table, a user was able to specify files on the server and when their format is supported by the used PhpSpreadsheet library they would be included and their content leaked to the user. It is recommended that the Nextcloud Tables app is upgraded to 0.7.6, 0.8.8 or 0.9.5.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
