Authenticated session compromise via exposed PDF.js viewer
Published Dec 4, 2025 · Updated Dec 11, 2025
Cross-site scripting in Nextcloud Server allows remote authenticated users to access a logged-in victim's files via a crafted PDF link. The files_pdfviewer app exposes PDF.js's unused web/viewer.html example on the Nextcloud origin, where it renders a malicious uploaded PDF and runs embedded JavaScript. Exploitation requires a regular account able to upload and publicly share the PDF, plus a logged-in victim who opens the prepared link; the script acts with that victim's Nextcloud identity.
Summary
What happened
Cross-site scripting in Nextcloud Server allows remote authenticated users to access a logged-in victim's files via a crafted PDF link. The files_pdfviewer app exposes PDF.js's unused web/viewer.html example on the Nextcloud origin, where it renders a malicious uploaded PDF and runs embedded JavaScript. Exploitation requires a regular account able to upload and publicly share the PDF, plus a logged-in victim who opens the prepared link; the script acts with that victim's Nextcloud identity.
The record
- CVE
- CVE-2025-59788
- Published
- Dec 4, 2025
- Updated
- Dec 11, 2025
- Vendor
- Nextcloud GmbH
- Product
- Nextcloud Server
- Classifications
- CWE-79, T1204.001
- Attack vector
- network
- Privileges
- authenticated
Timeline
How it unfolded
- Dec 4, 2025CVE publishedPublication date reported by the CVE source.
- Dec 11, 2025Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=0 <22.2.10.33
- Affected versionversion=23 <23.0.12.29
- Affected versionversion=24 <24.0.12.28
- Affected versionversion=25 <25.0.13.23
- Affected versionversion=26 <26.0.13.20
- Affected versionversion=27 <27.1.11.20
- Affected versionversion=28 <28.0.14.11
- Affected versionversion=29 <29.0.16.8
- Affected versionversion=30 <30.0.17
- Affected versionversion=31 <31.0.10
- Affected versionversion=32 <32.0.1
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- RedTeam Pentesting crafted-PDF proof of conceptproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo