CVE-2019-12739: Nextcloud Extract
High severity, CVSS 8.8. EPSS: 2.5% chance of exploitation in the next 30 days.
lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution via shell metacharacters in a RAR filename via ajax/extractRar.php (nameOfFile and directory parameters).
Affected products
- Nextcloud Extract: before 1.2.0 (fixed in 1.2.0)
Published 2019-06-05. Last modified 2026-06-17.