Nextcloud Flow – Critical RCE Vulnerability via Windmill Component
A flaw in the Windmill component of Nextcloud's 'Flow' automation app allows attackers to steal administrator tokens and execute arbitrary code with root privileges. Self-hosted Nextcloud instances are fully at risk.
What happened?
A critical vulnerability has been discovered in Nextcloud's automation app "Flow". A flaw in the underlying Windmill component allows attackers to steal administrator tokens and execute arbitrary code on the server. Since execution typically occurs with root privileges inside the container, a successful compromise puts the entire Nextcloud instance at risk — including all stored files, user accounts, and connected services.
Affected versions are Flow app releases prior to 1.3.0. A patch is available.
Who is affected?
- SMEs hosting Nextcloud as a self-managed collaboration platform
- Users of the "Nextcloud Flow" app (particularly versions before 1.3.0)
- IT service providers in CH/FL operating managed Nextcloud instances for customers
Particularly exposed: instances reachable from the internet where the Flow app is actively used.
What should you do?
- Immediate update: Update the Flow app to version 1.3.0 or later without delay — via the Nextcloud App Store or CLI (
occ app:update flow). - Workaround: If an immediate update is not feasible, disable the Flow app in the Nextcloud settings and stop all associated Windmill containers.
- Audit: Check whether the file
windmill_users_config.jsonhas already been accessed unauthorised — carefully review access logs of the affected instance. - Hardening: Ensure your Nextcloud instance is configured according to the hardening guidelines — a practical reference is available in the Nextcloud documentation.
This advisory is for informational purposes. Contact us for a security review of your Nextcloud instance.
Ready to know your attack surface?
Tell us briefly about your project — we'll come back with a concrete proposal.
Request a first call