Nixpkgs Security Tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for a revision.

updated 3 days, 1 hour ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    17 packages
    • atlas
    • nim-atlas
    • atlassian-cli
    • ripe-atlas-tools
    • mongodb-atlas-cli
    • atlassian-plugin-sdk
    • haskellPackages.atlas
    • prometheus-atlas-exporter
    • python312Packages.chatlas
    • python313Packages.chatlas
    • terraform-providers.mongodbatlas
    • python312Packages.ripe-atlas-sagan
    • python313Packages.ripe-atlas-sagan
    • python312Packages.ripe-atlas-cousteau
    • python313Packages.ripe-atlas-cousteau
    • python312Packages.atlassian-python-api
    • python313Packages.atlassian-python-api
  • @LeSuisse dismissed
WordPress Atlas theme <= 2.1.0 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TMRW-studio Atlas atlas allows PHP Local File Inclusion.This issue affects Atlas: from n/a through <= 2.1.0.

Affected products

atlas
  • =<<= 2.1.0

Matching in nixpkgs

Package maintainers: 8

updated 3 days, 1 hour ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    2 packages
    • python312Packages.pathos
    • python313Packages.pathos
  • @LeSuisse dismissed
WordPress Athos theme <= 1.9 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Athos athos allows PHP Local File Inclusion.This issue affects Athos: from n/a through <= 1.9.

Affected products

athos
  • =<<= 1.9

Matching in nixpkgs

updated 3 days, 1 hour ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    3 packages
    • typstPackages.unequivocal-ams_0_1_2
    • typstPackages.unequivocal-ams_0_1_1
    • typstPackages.unequivocal-ams_0_1_0
  • @LeSuisse dismissed
WordPress Vocal theme <= 1.12 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Vocal vocal allows PHP Local File Inclusion.This issue affects Vocal: from n/a through <= 1.12.

Affected products

vocal
  • =<<= 1.12

Matching in nixpkgs

Package maintainers: 1

updated 3 days, 1 hour ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    12 packages
    • health-check
    • grpc-health-check
    • python312Packages.django-health-check
    • python313Packages.django-health-check
    • rubyPackages.github-pages-health-check
    • python312Packages.grpcio-health-checking
    • python313Packages.grpcio-health-checking
    • rubyPackages_3_1.github-pages-health-check
    • rubyPackages_3_2.github-pages-health-check
    • rubyPackages_3_3.github-pages-health-check
    • rubyPackages_3_4.github-pages-health-check
    • rubyPackages_3_5.github-pages-health-check
  • @LeSuisse dismissed
WordPress Health Check & Troubleshooting plugin <= 1.7.1 - Path Traversal vulnerability

Path Traversal: '.../...//' vulnerability in WordPress.org Health Check & Troubleshooting health-check allows Path Traversal.This issue affects Health Check & Troubleshooting: from n/a through <= 1.7.1.

Affected products

health-check
  • =<<= 1.7.1

Matching in nixpkgs

Package maintainers: 4

updated 3 days, 1 hour ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    25 packages
    • redpanda-client
    • python312Packages.pandas
    • python313Packages.pandas
    • python312Packages.biopandas
    • python312Packages.geopandas
    • python312Packages.pandantic
    • python312Packages.pandas-ta
    • python313Packages.biopandas
    • python313Packages.geopandas
    • python313Packages.pandantic
    • python313Packages.pandas-ta
    • python312Packages.pint-pandas
    • python313Packages.pint-pandas
    • python312Packages.pandas-stubs
    • python313Packages.pandas-stubs
    • python312Packages.awkward-pandas
    • python312Packages.netdata-pandas
    • python313Packages.awkward-pandas
    • python313Packages.netdata-pandas
    • python312Packages.geoarrow-pandas
    • python313Packages.geoarrow-pandas
    • pkgsRocm.python3Packages.pandantic
    • python312Packages.prometheus-pandas
    • python313Packages.prometheus-pandas
    • pkgsRocm.python3Packages.pandas-stubs
  • @LeSuisse dismissed
WordPress Panda theme <= 1.21 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Panda panda allows PHP Local File Inclusion.This issue affects Panda: from n/a through <= 1.21.

Affected products

panda
  • =<<= 1.21

Matching in nixpkgs

Package maintainers: 19

updated 3 days, 1 hour ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    5 packages
    • python313Packages.pypitoken
    • python312Packages.pypitoken
    • python313Packages.auditok
    • python312Packages.auditok
    • scitokens-cpp
  • @LeSuisse dismissed
WordPress ITok theme <= 1.1.42 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme ITok itok.This issue affects ITok: from n/a through <= 1.1.42.

Affected products

itok
  • =<<= 1.1.42

Matching in nixpkgs

Package maintainers: 2

updated 3 days, 1 hour ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    2 packages
    • l-smash
    • git-smash
  • @LeSuisse dismissed
WordPress Smash theme <= 1.7 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Smash smash allows PHP Local File Inclusion.This issue affects Smash: from n/a through <= 1.7.

Affected products

smash
  • =<<= 1.7

Matching in nixpkgs

Package maintainers: 1

updated 3 days, 1 hour ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    4 packages
    • basilk
    • basiliskii
    • typstPackages.dmi-basilea-thesis_0_1_0
    • typstPackages.dmi-basilea-thesis_0_1_1
  • @LeSuisse dismissed
WordPress Basil theme <= 1.3.12 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Basil basil allows PHP Local File Inclusion.This issue affects Basil: from n/a through <= 1.3.12.

Affected products

basil
  • =<<= 1.3.12

Matching in nixpkgs

Package maintainers: 3

updated 3 days, 14 hours ago by @mweinelt Activity log
  • Created automatic suggestion
  • @mweinelt dismissed
HCL AION is affected by an Unrestricted File Upload vulnerability

HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.

Affected products

AION
  • ==2

Matching in nixpkgs

pkgs.python312Packages.aionanoleaf

Python wrapper for the Nanoleaf API

pkgs.python313Packages.aionanoleaf

Python wrapper for the Nanoleaf API

pkgs.python312Packages.electrum-aionostr

Asyncio nostr client

pkgs.python313Packages.electrum-aionostr

Asyncio nostr client

Package maintainers: 2

updated 3 days, 20 hours ago by @mweinelt Activity log
  • Created automatic suggestion
  • @mweinelt dismissed
birkir prime GraphQL API graphql information disclosure

A vulnerability was detected in birkir prime up to 0.4.0.beta.0. This issue affects some unknown processing of the file /graphql of the component GraphQL API. Performing a manipulation results in information disclosure. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

prime
  • ==0.4.0.beta

Matching in nixpkgs

pkgs.primecount

Fast prime counting function implementations

pkgs.prime-server

Non-blocking (web)server API for distributed computing and SOA based on zeromq

pkgs.CuboCore.libcprime

Library for bookmarking, saving recent activites, managing settings of C-Suite

pkgs.rubyPackages_3_5.prime

None

pkgs.haskellPackages.nth-prime

Computing the nth prime

pkgs.python312Packages.msprime

Simulate genealogical trees and genomic sequence data using population genetic models

pkgs.python312Packages.primepy

This module contains several useful functions to work with prime numbers. from primePy import primes

pkgs.python313Packages.msprime

Simulate genealogical trees and genomic sequence data using population genetic models

pkgs.python313Packages.primepy

This module contains several useful functions to work with prime numbers. from primePy import primes

pkgs.haskellPackages.primesieve

FFI bindings for the primesieve library

pkgs.perlPackages.MathPrimeUtil

Utilities related to prime numbers, including fast sieves and factoring

pkgs.haskellPackages.prelude-prime

A slightly better (but conservative) Prelude

pkgs.perl538Packages.MathPrimeUtil

Utilities related to prime numbers, including fast sieves and factoring

pkgs.perl540Packages.MathPrimeUtil

Utilities related to prime numbers, including fast sieves and factoring

pkgs.perlPackages.MathPrimeUtilGMP

Utilities related to prime numbers, using GMP

pkgs.perlPackages.MathProvablePrime

Generate a provable prime number, in pure Perl

pkgs.python312Packages.primecountpy

Cython interface for C++ primecount library

pkgs.python313Packages.primecountpy

Cython interface for C++ primecount library

pkgs.haskellPackages.opentheory-prime

Prime natural numbers

pkgs.perl538Packages.MathPrimeUtilGMP

Utilities related to prime numbers, using GMP

pkgs.perl540Packages.MathPrimeUtilGMP

Utilities related to prime numbers, using GMP

pkgs.perl538Packages.MathProvablePrime

Generate a provable prime number, in pure Perl

pkgs.perl540Packages.MathProvablePrime

Generate a provable prime number, in pure Perl

pkgs.rubyPackages_3_1.jekyll-theme-primer

None

pkgs.rubyPackages_3_2.jekyll-theme-primer

None

pkgs.rubyPackages_3_5.jekyll-theme-primer

None

Package maintainers: 14