CVE-2025-66208 | CollaboraOnline up to 25.04.701 Built-in CODE Server App proxy.php os command injection (GHSA-j3q6-q5pc-v5wf)
A vulnerability labeled as critical has been found in CollaboraOnline Online up to 25.04.701. Affected is an unknown function of the file proxy.php of the component Built-in CODE Server App. Such manipulation leads to os command injection.
This vulnerability is referenced as CVE-2025-66208. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.