---
id: CVE-2025-66551
title: Nextcloud Tables allows you to create your own tables with individual columns
summary: >-
  Nextcloud Tables allows you to create your own tables with individual columns.
  Prior to 0.8.6 and 0.9.3, a malicious user was able to create their own table
  and then move a column to a victims table. This vulnerability is fixed in
  0.8.6 …
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L'
cwe:
  - CWE-639
vendor: nextcloud
product: tables
affected:
  - 'tables >= 0.4.0, < 0.8.6'
  - 'tables >= 0.9.0, < 0.9.3'
patched:
  - tables 0.9.3
published: '2025-12-05'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-66551'
references:
  - url: >-
      https://github.com/nextcloud/security-advisories/security/advisories/GHSA-w787-vwqp-8wr7
    label: security-advisories@github.com
  - url: >-
      https://github.com/nextcloud/tables/commit/39f24a62fb41fd7a8bda65325f8bbafdc91c731c
    label: security-advisories@github.com
  - url: 'https://github.com/nextcloud/tables/pull/1810'
    label: security-advisories@github.com
  - url: 'https://hackerone.com/reports/3137895'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00253
epssPercentile: 0.15048
ingestedAt: '2026-09-25T23:21:16.897Z'
---

## Overview

Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.6 and 0.9.3, a malicious user was able to create their own table and then move a column to a victims table. This vulnerability is fixed in 0.8.6 and 0.9.3.

## Affected

- `tables >= 0.4.0, < 0.8.6`
- `tables >= 0.9.0, < 0.9.3`

## Remediation

Upgrade past the affected range:

- `tables 0.9.3`
