Nextcloud Approval App Workflow Vulnerability Allowing Unauthorized File Approval
Vulnerability
A vulnerability in the Nextcloud Approval app prior to versions 1.3.1 and 2.5.0 allows authenticated users listed as requesters in a workflow to place another user's file into 'pending approval' status without having access to the file. This is achieved by using the numeric file ID.
Impact
This vulnerability could lead to unauthorized file approval actions within the Nextcloud Approval app, disrupting workflow processes.
Remediation
Users are advised to upgrade the Nextcloud Approval app to version 2.5.0 or 1.3.1. Alternatively, the Approval app can be disabled.
Added: Dec 5, 2025, 6:29 PM
Updated: Dec 5, 2025, 6:29 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.6exploitability
5.0remediation
0.0relevance
1.3threat
3.2urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
