Low severity3.5NVD Advisory· Published Dec 5, 2025· Updated Jun 17, 2026
CVE-2025-66554
CVE-2025-66554
Description
Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. Prior to 5.5.4, 6.0.6, and 7.2.5, a malicious user was able to modify their organisation and title field to load additional CSS files. Javascript and other options were correctly blocked by the content security policy of the Nextcloud Server code. This vulnerability is fixed in 5.5.4, 6.0.6, and 7.2.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: >= 7.0.0-alpha.1, < 7.2.5
Patches
Vulnerability mechanics
References
4- github.com/nextcloud/contacts/commit/d954d098978dde1f121600e8b994e02f293c68b1nvdPatch
- github.com/nextcloud/contacts/pull/4619nvdIssue TrackingPatch
- github.com/nextcloud/security-advisories/security/advisories/GHSA-9v78-cpfc-v6h2nvdPatchVendor Advisory
- hackerone.com/reports/3293290nvdPermissions RequiredVendor Advisory
News mentions
0No linked articles in our index yet.