CVE-2019-12739: Nextcloud Extract

High severity, CVSS 8.8. EPSS: 2.5% chance of exploitation in the next 30 days.

lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution via shell metacharacters in a RAR filename via ajax/extractRar.php (nameOfFile and directory parameters).

Affected products

  • Nextcloud Extract: before 1.2.0 (fixed in 1.2.0)

Published 2019-06-05. Last modified 2026-06-17.