Medium severity5.4NVD Advisory· Published Jul 6, 2022· Updated Jun 17, 2026
CVE-2022-31131
CVE-2022-31131
Description
Nextcloud mail is a Mail app for the Nextcloud home server product. Versions of Nextcloud mail prior to 1.12.2 were found to be missing user account ownership checks when performing tasks related to mail attachments. Attachments may have been exposed to incorrect system users. It is recommended that the Nextcloud Mail app is upgraded to 1.12.2. There are no known workarounds for this issue.
Workarounds
No workaround available
References * Pull request * HackerOne
For more information
If you have any questions or comments about this advisory: * Create a post in nextcloud/security-advisories * Customers: Open a support ticket at support.nextcloud.com
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- nextcloud/security-advisoriesv5Range: < 1.12.2
Patches
Vulnerability mechanics
References
3- github.com/nextcloud/mail/pull/6600nvdIssue TrackingPatchThird Party Advisory
- github.com/nextcloud/mail/pull/6600/commits/6dd2527be8d4f6788b449c8a8f5577628b990605nvdPatchThird Party Advisory
- github.com/nextcloud/security-advisories/security/advisories/GHSA-xhv7-5mhv-299jnvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.