Nextcloud Approval App Workflow Vulnerability Allowing Unauthorized File Approval

Vulnerability

A vulnerability in the Nextcloud Approval app prior to versions 1.3.1 and 2.5.0 allows authenticated users listed as requesters in a workflow to place another user's file into 'pending approval' status without having access to the file. This is achieved by using the numeric file ID.

Impact

This vulnerability could lead to unauthorized file approval actions within the Nextcloud Approval app, disrupting workflow processes.

Remediation

Users are advised to upgrade the Nextcloud Approval app to version 2.5.0 or 1.3.1. Alternatively, the Approval app can be disabled.

Added: Dec 5, 2025, 6:29 PM
Updated: Dec 5, 2025, 6:29 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.0
remediation
0.0
relevance
1.3
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.