This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
Summary
AI summaryProperly escape all bash arguments in ncp‑web to fix a security vulnerability.
Full changelog
v1.57.1 (2026-04-14) Various fixes
Included Software
Nextcloud 33.0.2 (can be automatically updated to latest minor version)
PHP 8.3
Debian bookworm
Armbian
Fixes
- Fail gracefully when parsing invalid backup cache (#2105, thanks @Dominik0101)
- security: Properly escape all bash arguments in ncp-web (ncp-launcher.php)
- Make sure, sury repository key is updated from pkg sources (fixes #2104)
- Fix broken ncp-preview-generator cronjob script (fixes #2107)
Checksums:
1e06609bfb455631532426834b25ae17 NextcloudPi_OdroidC4_v1.57.1.zip
bf780db004ca2a00be0725a15202deaf NextcloudPi_OrangePi5Plus_v1.57.1.zip
bd6993b052b71f6e994cd7fd9f793c8a NextcloudPi_RaspberryPi 4+_v1.57.1.zip
378c83331daf3e380bedc5fc434b1647 NextcloudPi_OrangePi5_v1.57.1.zip
9474fa8279ba2013faf25d813c72c056 NextcloudPi_OdroidC2_v1.57.1.zip
d1490637de80f3c94b5ffbd94384ebcf NextcloudPi_RockPro64_v1.57.1.zip
57fa6ac09618436a8e8eca9f99f30890 NextcloudPi_OdroidHC4_v1.57.1.zip
33fb6563475f9d9f3a708c011b619d5e NextcloudPi_Rock64_v1.57.1.zip
4cce987da86ed340230bb6e44c351168 NextcloudPi_LXC_arm64_v1.57.1.tar.gz
52888e2dda6784bc4d82f98971eb201f NextcloudPi_LXD_arm64_v1.57.1.tar.gz
f48780c558dfb62ffa3a3d6779d3dd04 NextcloudPi_LXC_x86_v1.57.1.tar.gz
e4d11d9ed446b00923b0bc8dc9148d43 NextcloudPi_LXD_x86_v1.57.1.tar.gz
Security Fixes
- Properly escape all bash arguments in ncp‑web (ncp-launcher.php) – fixes a security vulnerability
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About NextCloudPi
Nextcloud preinstalled and preconfigured, with a text and web management interface and all the tools needed to self host private data. With installation images for Raspberry Pi, Odroid, Rock64, Docker, and a curl installer for Armbian/Debian. `GPL-2.0` `Shell/PHP`
Beta — feedback welcome: [email protected]