Pubblicato il 2026-08-25 · Fonte: NVD NIST
Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud instance. Prior to 0.117.2, the POST /webhooks/nextcloud endpoint in nextcloud_mcp_server/vector/webhook_receiver.py has no authentication by default because WEBHOOK_SECRET defaults to None and startup validation does not require it. When WEBHOOK_SECRET is unset, handle_nextcloud_webhook() accepts unauthenticated requests. The payload["user"]["uid"] field parsed in nextcloud_mcp_server/vector/webhook
Vulnerabilità con punteggio CVSS 9.1 (CRITICAL). Sfruttata attivamente: No.
Vendor: N/A
Prodotti: N/A
Applicare le patch del vendor appena disponibili. Monitorare gli advisory ufficiali.
Vuoi approfondire la cybersecurity? Scopri il libro "Ethical Hacker per Tutti" oppure prenota una lezione online.