Executive brief
Nextcloud is an open-source collaboration platform for file sharing and communication. A security flaw in its OpenID Connect (OIDC) login component allows attackers to create malicious links that redirect users to external, untrusted websites after they log in. This could be used in phishing campaigns to trick users into visiting fraudulent sites that mimic the legitimate platform to steal further credentials or deliver malware.
Technical details
An open redirect vulnerability (CWE-601) exists in the Nextcloud User OIDC application between versions 6.1.0 and 8.2.1. The flaw is caused by a protocol-relative URL bypass in the login flow's redirect URL validation logic. An attacker can craft a malicious link that, upon successful OIDC authentication by a victim, redirects the browser to an arbitrary external domain. While the CVSS vector indicates local access, this typically refers to the requirement of user interaction (clicking a link) to trigger the redirect. The issue is resolved in version 8.2.2 by improving the checks used to prevent absolute or protocol-relative URLs in the redirect parameter.
Affected products
- Nextcloud User OIDC app 6.1.0 to 8.2.1
Timeline
- 2025-12-17: patched: Initial pull request to improve redirect URL checks merged.
- 2026-05-12: advisory: GitHub security advisory published.
- 2026-06-01: disclosed: CVE-2026-45278 published to NVD.