Impact
The Photos app’s smart albums use the viewer’s folder configuration, not the owner’s, causing the recipient to discover the owner’s hidden file names, identifiers, and other metadata. This is an information‑disclosure flaw that reveals data the owner intended to keep private.
Affected Systems
Nextcloud Server, with the Photos app module, is affected. No specific version is provided in the CVE record.
Risk and Exploitability
The CVSS score of 6.5 denotes moderate severity, and the EPSS score of less than 1% indicates the vulnerability is not expected to be widely exploited. This flaw is not listed in CISA’s KEV catalog. Exploitation requires that the owner shares a filter-based smart album. Based on the description, the likely attack vector is the Photos web interface or API used after a legitimate sharing event.
OpenCVE Enrichment