Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language into the Desktop Client application. It is recommended that the Nextcloud Desktop client is upgraded to 3.6.1. There are no known workarounds for this issue.
References
| Link | Resource |
|---|---|
| https://github.com/nextcloud/desktop/pull/4972 | Patch Third Party Advisory |
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-92p9-x79h-2mj8 | Third Party Advisory |
| https://hackerone.com/reports/1711847 | Exploit Third Party Advisory |
| https://github.com/nextcloud/desktop/pull/4972 | Patch Third Party Advisory |
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-92p9-x79h-2mj8 | Third Party Advisory |
| https://hackerone.com/reports/1711847 | Exploit Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2025/09/msg00018.html |
Configurations
History
03 Nov 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Nov 2024, 07:18
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.6 |
| References | () https://github.com/nextcloud/desktop/pull/4972 - Patch, Third Party Advisory | |
| References | () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-92p9-x79h-2mj8 - Third Party Advisory | |
| References | () https://hackerone.com/reports/1711847 - Exploit, Third Party Advisory |
01 Dec 2022, 17:39
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
| CPE | cpe:2.3:a:nextcloud:desktop:*:*:*:*:*:*:*:* | |
| References | (CONFIRM) https://github.com/nextcloud/security-advisories/security/advisories/GHSA-92p9-x79h-2mj8 - Third Party Advisory | |
| References | (MISC) https://hackerone.com/reports/1711847 - Exploit, Third Party Advisory | |
| References | (MISC) https://github.com/nextcloud/desktop/pull/4972 - Patch, Third Party Advisory |
26 Nov 2022, 03:14
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2022-11-25 20:15
Updated : 2025-11-03 19:15
NVD link : CVE-2022-39333
Mitre link : CVE-2022-39333
CVE.ORG link : CVE-2022-39333
JSON object : View
Products Affected
nextcloud
- desktop
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
