Skip to main content
Vulnerability Database/CVE-2025-59788

CVE-2025-59788: Nextcloud Server XSS Vulnerability

CVE-2025-59788 is a cross-site scripting vulnerability in Nextcloud Server affecting multiple versions. Attackers can execute JavaScript via crafted PDF files. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2025-59788 Overview

CVE-2025-59788 is a cross-site scripting (XSS) vulnerability in Nextcloud Server. The flaw exists in a reachable files_pdfviewer example directory that exposes executable example code on a same-origin basis. Attackers can execute arbitrary JavaScript in the context of a user's browser by delivering a crafted PDF file to viewer.html. The issue is related to CVE-2024-4367 in PDF.js, but the Nextcloud-specific root cause is the exposure of the vulnerable example viewer on the same origin as the application [CWE-79, CWE-749].

Critical Impact

An authenticated attacker can execute JavaScript in the victim's browser session, enabling session token theft, unauthorized file access, and cross-user data exposure within the Nextcloud instance.

Affected Products

  • Nextcloud Server versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20
  • Nextcloud Server versions before 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, 32.0.1
  • Nextcloud Server Enterprise editions covering the same version ranges

Discovery Timeline

  • 2025-12-04 - CVE-2025-59788 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-59788

Vulnerability Analysis

The vulnerability resides in the files_pdfviewer application shipped with Nextcloud Server. This component includes example code and a viewer.html file that remains reachable from the browser after installation. Because the file is served from the same origin as the main Nextcloud application, JavaScript executed within it inherits access to session cookies and application APIs.

The underlying rendering logic is affected by the PDF.js issue tracked as CVE-2024-4367, which allows script execution through crafted PDF font metadata. Nextcloud's exposure of the example viewer to authenticated users turns that library issue into an application-level XSS vector. Successful exploitation requires user interaction to open the malicious PDF through the vulnerable viewer path.

Root Cause

The root cause is the exposure of executable example code on a same-origin basis, mapped to [CWE-749: Exposed Dangerous Method or Function] combined with [CWE-79: Improper Neutralization of Input During Web Page Generation]. Example and demo files bundled with files_pdfviewer should not be routable from a production deployment, yet the shipped configuration leaves viewer.html reachable.

Attack Vector

An attacker with low-privileged access uploads or links a crafted PDF file that abuses the PDF.js parsing weakness. The victim opens the file through the exposed viewer.html endpoint. The malicious payload executes JavaScript in the victim's browser under the Nextcloud origin, enabling actions such as reading files, exfiltrating tokens, or issuing API requests on the victim's behalf.

A sanitized description of the exploitation chain: the attacker crafts a PDF containing a specially formed font FontMatrix value that PDF.js interprets as JavaScript when rendering. When the victim loads the file via the exposed example viewer, the script runs in the Nextcloud origin context. Refer to the RedTeam PenTesting Advisory RT-SA-2025-003 and the GitHub Security Advisory GHSA-24wp-p865-7j4r for full technical detail.

Detection Methods for CVE-2025-59788

Indicators of Compromise

  • HTTP GET requests to paths containing /apps/files_pdfviewer/ and viewer.html with a file= parameter referencing user-supplied PDFs
  • PDF uploads containing embedded JavaScript within font descriptors or FontMatrix fields
  • Unexpected outbound requests from browser sessions immediately after opening a PDF in Nextcloud

Detection Strategies

  • Inspect web server access logs for requests to the files_pdfviewer example viewer path from authenticated user sessions
  • Deploy a Content Security Policy (CSP) in report-only mode to surface script executions originating from the viewer path
  • Scan uploaded PDF files for embedded JavaScript keywords such as /JS, /JavaScript, and suspicious FontMatrix entries

Monitoring Recommendations

  • Alert on anomalous API activity that follows a PDF open event, including bulk file downloads or share creation actions
  • Correlate authentication events with subsequent viewer.html accesses to identify session hijack attempts
  • Track Nextcloud application version inventory to confirm all instances are on a patched release

How to Mitigate CVE-2025-59788

Immediate Actions Required

  • Upgrade Nextcloud Server to a fixed release: 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, or 32.0.1 or later
  • Disable the files_pdfviewer application if patching cannot be completed immediately
  • Rotate active user session tokens after patching to invalidate any compromised sessions

Patch Information

Nextcloud published fixes across all supported branches. Details and remediation guidance are available in the Nextcloud Security Advisory GHSA-24wp-p865-7j4r. Enterprise customers should apply the corresponding enterprise patch level for their deployed branch.

Workarounds

  • Block access to the files_pdfviewer example directory at the reverse proxy or web server layer
  • Enforce a strict Content Security Policy that disallows inline script execution on the Nextcloud origin
  • Restrict PDF viewing to trusted internal users until the upgrade is deployed
bash
# Example NGINX rule to block the vulnerable example viewer path
location ~* /apps/files_pdfviewer/.*viewer\.html {
    deny all;
    return 403;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.