The Nextcloud Approval app allows approval or disapproval of files in the sidebar. Prior to 1.3.1 and 2.5.0, an authenticated user listed as a requester in a workflow can set another user’s file into the “pending approval” without access to the file by using the numeric file id. This vulnerability is fixed in 1.3.1 and 2.5.0.
2025-12-05T18:15:57.623
2025-12-09T17:22:18.077
Analyzed
CVSSv3.1: 2.7 (LOW)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | nextcloud | approval | < 1.3.1 | Yes |
| Application | nextcloud | approval | < 2.5.0 | Yes |