You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Approval app allows users to request approval for other users file
Low
nickvergessen
published
GHSA-q26g-fmjq-x5g5Dec 5, 2025
Package
Approval
(Nextcloud)
Affected versions
>= 1.0.0, >= 2.0.0
Patched versions
1.3.1, 2.5.0
Description
Impact
An authenticated user listed as a requester in a workflow can set another user’s file into the “pending approval” without access to the file by using the numeric file id.
Patches
It is recommended that Nextcloud Approval is upgraded to 2.5.0.
Impact
An authenticated user listed as a requester in a workflow can set another user’s file into the “pending approval” without access to the file by using the numeric file id.
Patches
It is recommended that Nextcloud Approval is upgraded to 2.5.0.
Workarounds
References
For more information
If you have any questions or comments about this advisory: