CVE-2025-66548 | Nextcloud Deck up to 1.12.6/1.14.3/1.15.0 File Extension escape output (GHSA-xjvq-xvr7-xpg6)
A vulnerability classified as problematic was found in Nextcloud Deck up to 1.12.6/1.14.3/1.15.0. Affected by this issue is some unknown functionality of the component File Extension Handler. Such manipulation leads to escaping of output.
This vulnerability is traded as CVE-2025-66548. An attack has to be approached locally. There is no exploit available.
Upgrading the affected component is advised.