Published issues
updated
3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 hours ago
-
@LeSuisse
accepted
3 hours ago
-
@LeSuisse
published on GitHub
3 hours ago
Apache Airflow: Event Log detail endpoint bypasses DAG-scoped event log permission filter
The Event Log detail endpoint `GET /api/v2/eventLogs/{event_log_id}` in Apache Airflow fetched audit-log rows directly by numeric ID after only the generic Audit Log permission check, while the collection endpoint `GET /api/v2/eventLogs` applied per-Dag scoping. An authenticated UI/API user with audit-log read permission for one Dag could retrieve audit-log entries for any other Dag by guessing or enumerating the numeric event log ID. Affects deployments that rely on per-Dag audit-log scoping. Users are advised to upgrade to `apache-airflow` 3.2.2 or later.
Matching in nixpkgs
Platform to programmatically author, schedule and monitor workflows
-
-
-
nixos-25.11-small
2.7.3
-
nixpkgs-25.11-darwin
2.7.3
Permalink
CVE-2026-48559
5.1 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): Passive (P)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): Low (L)
-
Subsequent System Impact Integrity (SI): Low (L)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): Passive (P)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Low (L)
-
Modified Subsequent System Impact Integrity (MSI): Low (L)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 hours ago
-
@LeSuisse
ignored
2 packages
3 hours ago
-
@LeSuisse
ignored
reference https://w…
3 hours ago
-
@LeSuisse
ignored
24 packages
- llmserve
- lmstudio
- python312Packages.calmsize
- python313Packages.calmsize
- python313Packages.lmstudio
- python314Packages.calmsize
- python314Packages.lmstudio
- python312Packages.llama-index-llms-ollama
- python312Packages.llama-index-llms-openai
- python313Packages.llama-index-llms-ollama
- python313Packages.llama-index-llms-openai
- python312Packages.llama-index-llms-openai-like
- python313Packages.llm-lmstudio
- python314Packages.llm-lmstudio
- pkgsRocm.python3Packages.llama-index-llms-ollama
- pkgsRocm.python3Packages.llama-index-llms-openai
- pkgsRocm.python3Packages.llama-index-llms-openai-like
- python312Packages.llama-index-multi-modal-llms-openai
- python313Packages.llama-index-multi-modal-llms-openai
- pkgsRocm.python3Packages.llama-index-multi-modal-llms-openai
- python313Packages.llama-index-llms-openai-like
- python314Packages.dlms-cosem
- python312Packages.dlms-cosem
- python313Packages.dlms-cosem
3 hours ago
-
@LeSuisse
accepted
3 hours ago
-
@LeSuisse
published on GitHub
3 hours ago
Lightweight Music Server 3.76.0 Stored XSS via Media File Metadata Tags
Lightweight Music Server (LMS) though 3.76.0 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by embedding malicious HTML in media file metadata tags such as GENRE, ARTIST, or ALBUM. Attackers can introduce a crafted media file into the victim's library, causing the payload to be saved during library scanning and executed automatically in the web interface due to tag content being rendered using Wt::TextFormat::UnsafeXHTML without sanitization in src/lms/ui/Utils.cpp.
Matching in nixpkgs
Lightweight Music Server - Access your self-hosted music using a web interface
Ignored packages (26)
Digital modem message program
Helm Charts (k8s applications) as Code tool
-
-
-
nixos-25.11-small
4.0.1
-
nixpkgs-25.11-darwin
4.0.1
TUI for serving local LLM models
LM Studio is an easy to use desktop app for experimenting with local and open-source Large Language Models (LLMs)
Take a number of bytes and return a human-readable string
-
-
nixos-25.11-small
0.1.3
-
nixpkgs-25.11-darwin
0.1.3
Take a number of bytes and return a human-readable string
-
-
-
nixos-25.11-small
0.1.3
-
nixpkgs-25.11-darwin
0.1.3
Take a number of bytes and return a human-readable string
Python module to parse DLMS/COSEM
Python module to parse DLMS/COSEM
Python module to parse DLMS/COSEM
Plugin to use local models via LM Studio API with https://llm.datasette.io
Plugin to use local models via LM Studio API with https://llm.datasette.io
LlamaIndex LLMS Integration for ollama
-
-
nixos-25.11-small
0.9.0
-
nixpkgs-25.11-darwin
0.9.0
LlamaIndex LLMS Integration for OpenAI
-
-
nixos-25.11-small
0.6.9
-
nixpkgs-25.11-darwin
0.6.9
LlamaIndex LLMS Integration for ollama
-
-
-
nixos-25.11-small
0.9.0
-
nixpkgs-25.11-darwin
0.9.0
LlamaIndex LLMS Integration for OpenAI
-
-
-
nixos-25.11-small
0.6.9
-
nixpkgs-25.11-darwin
0.6.9
LlamaIndex LLMS Integration for OpenAI like
-
-
nixos-25.11-small
0.5.3
-
nixpkgs-25.11-darwin
0.5.3
LlamaIndex LLMS Integration for OpenAI like
-
-
-
nixos-25.11-small
0.5.3
-
nixpkgs-25.11-darwin
0.5.3
LlamaIndex LLMS Integration for ollama
-
-
-
nixos-25.11-small
0.9.0
-
nixpkgs-25.11-darwin
0.9.0
LlamaIndex LLMS Integration for OpenAI
-
-
-
nixos-25.11-small
0.6.9
-
nixpkgs-25.11-darwin
0.6.9
LlamaIndex LLMS Integration for OpenAI like
-
-
-
nixos-25.11-small
0.5.3
-
nixpkgs-25.11-darwin
0.5.3
LlamaIndex Multi-Modal-Llms Integration for OpenAI
-
-
nixos-25.11-small
0.6.2
-
nixpkgs-25.11-darwin
0.6.2
LlamaIndex Multi-Modal-Llms Integration for OpenAI
-
-
nixos-25.11-small
0.6.2
-
nixpkgs-25.11-darwin
0.6.2
LlamaIndex Multi-Modal-Llms Integration for OpenAI
-
-
nixos-25.11-small
0.6.2
-
nixpkgs-25.11-darwin
0.6.2
updated
3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 hours ago
-
@LeSuisse
accepted
3 hours ago
-
@LeSuisse
published on GitHub
3 hours ago
Apache Airflow: Authenticated RCE via XCom PATCH endpoint — XComUpdateBody missing FORBIDDEN_XCOM_KEYS validator
A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user with XCom write permission on a Dag to set XCom entries under reserved key names (e.g. `return_value`) that the matching POST endpoint already validated against `FORBIDDEN_XCOM_KEYS`. The endpoint also accepted serialized payload shapes the triggerer's deserializer treats as code; combined, this allowed RCE on the triggerer when the affected task next deferred. Affects deployments where untrusted users have XCom write permission on Dags that defer to the triggerer. This is a fix-bypass of CVE-2026-33858: PR #64148 added the `FORBIDDEN_XCOM_KEYS` validator only on the POST/set path; the PATCH path was not covered. Users who already upgraded for CVE-2026-33858 should additionally upgrade to `apache-airflow` 3.2.2 or later to cover the PATCH-path bypass.
Matching in nixpkgs
Platform to programmatically author, schedule and monitor workflows
-
-
-
nixos-25.11-small
2.7.3
-
nixpkgs-25.11-darwin
2.7.3
Permalink
CVE-2026-10267
1.9 LOW
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): Low (L)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Exploit Maturity (E): POC (P)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
updated
3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 hours ago
-
@LeSuisse
ignored
3 references
3 hours ago
-
@LeSuisse
ignored
6 packages
- vscode-extensions.janet-lang.vscode-janet
- tree-sitter-grammars.tree-sitter-janet-simple
- vimPlugins.nvim-treesitter-parsers.janet_simple
- python312Packages.tree-sitter-grammars.tree-sitter-janet-simple
- python313Packages.tree-sitter-grammars.tree-sitter-janet-simple
- python314Packages.tree-sitter-grammars.tree-sitter-janet-simple
3 hours ago
-
@LeSuisse
accepted
3 hours ago
-
@LeSuisse
published on GitHub
3 hours ago
janet-lang janet debug.c doframe out-of-bounds
A security flaw has been discovered in janet-lang janet up to 1.41.0. This affects the function doframe of the file src/core/debug.c. Performing a manipulation results in out-of-bounds read. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. The patch is named ed17dd2c5913a23fb1107251e44a9410a3c30cf5.
Affected products
janet
-
==1.26
-
==1.34
-
==1.15
-
==1.19
-
==1.10
-
==1.38
-
==1.28
-
==1.33
-
==1.18
-
==1.20
-
==1.6
-
==1.39
-
==1.40
-
==1.3
-
==1.1
-
==1.31
-
==1.27
-
==1.35
-
==1.36
-
==1.24
-
==1.11
-
==1.22
-
==1.25
-
==1.8
-
==1.29
-
==1.5
-
==1.12
-
==1.30
-
==1.13
-
==1.17
-
==1.4
-
==1.16
-
==1.21
-
==1.14
-
==1.0
-
==1.7
-
==1.2
-
==1.9
-
==1.41.0
-
==1.32
-
==1.37
-
==1.23
Matching in nixpkgs
Janet programming language
Ignored packages (6)
Janet language support for Visual Studio Code
-
-
-
nixos-25.11-small
0.0.2
-
nixpkgs-25.11-darwin
0.0.2
Tree-sitter grammar for janet-simple
Tree-sitter grammar for janet_simple
-
-
nixos-25.11
-
-
nixos-25.11-small
-
nixpkgs-25.11-darwin
Python bindings for tree-sitter-janet-simple
Python bindings for tree-sitter-janet-simple
Python bindings for tree-sitter-janet-simple
Permalink
CVE-2026-10233
1.9 LOW
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): Low (L)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Exploit Maturity (E): POC (P)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
updated
3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 hours ago
-
@LeSuisse
ignored
4 references
3 hours ago
-
@LeSuisse
accepted
3 hours ago
-
@LeSuisse
published on GitHub
3 hours ago
Assimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_sequence_infos out-of-bounds
A security vulnerability has been detected in Assimp up to 6.0.4. Affected by this issue is the function HL1MDLLoader::read_sequence_infos of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. The manipulation of the argument aiString leads to out-of-bounds read. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project tagged the reported issue as bug.
Affected products
Assimp
-
==6.0.3
-
==6.0.4
-
==6.0.2
-
==6.0.1
-
==6.0.0
Matching in nixpkgs
Library to import various 3D model formats
-
-
-
nixos-25.11-small
6.0.2
-
nixpkgs-25.11-darwin
6.0.2
updated
3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 hours ago
-
@LeSuisse
accepted
3 hours ago
-
@LeSuisse
published on GitHub
3 hours ago
Apache Airflow: revoke_token() unreachable in FabAuthManager / KeycloakAuthManager logout path
A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked logout in the UI: the logout flow for `FabAuthManager` and `KeycloakAuthManager` did not actually reach the underlying `revoke_token()` call, so the JWT remained accepted by the API server until its natural expiry. An attacker holding a previously-issued JWT for a logged-out user could continue to make authenticated API calls as that user. Affects deployments configured with `FabAuthManager` or `KeycloakAuthManager` (the bug does not affect SimpleAuthManager). This is a residual gap in the fix for CVE-2025-57735, which addressed cookie-side invalidation in PR #57992 / PR #61339 but did not cover the provider-side `revoke_token()` reachability in the FAB / Keycloak code paths. Users who already upgraded for CVE-2025-57735 should additionally upgrade to `apache-airflow` 3.2.2 or later to cover the FAB / Keycloak logout paths.
Matching in nixpkgs
Platform to programmatically author, schedule and monitor workflows
-
-
-
nixos-25.11-small
2.7.3
-
nixpkgs-25.11-darwin
2.7.3
Permalink
CVE-2026-45192
6.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): None (N)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): None (N)
updated
3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 hours ago
-
@LeSuisse
accepted
3 hours ago
-
@LeSuisse
published on GitHub
3 hours ago
Apache Airflow: Incomplete Redaction of Sensitive Fields in Connection Extra API Response
A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apache Airflow allowed an authenticated UI/API user with Connection-read permission to retrieve secrets stored in a Connection's `extra` JSON blob under field names not present in the redaction allowlist (`DEFAULT_SENSITIVE_FIELDS`) — for example, official Slack-provider credential field names were returned in plaintext. Affects deployments that store credentials in Connection `extra` blobs and grant Connection-read access to multiple users. Users are advised to upgrade to `apache-airflow` 3.2.2 or later. As a defense-in-depth mitigation, deployment operators can store sensitive credential values in a secret-backend rather than inlined into the Connection's `extra` field.
Matching in nixpkgs
Platform to programmatically author, schedule and monitor workflows
-
-
-
nixos-25.11-small
2.7.3
-
nixpkgs-25.11-darwin
2.7.3
Permalink
CVE-2026-48839
7.1 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Changed (C)
-
Confidentiality (C): Low (L)
-
Integrity (I): Low (L)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Changed (C)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): Low (L)
updated
3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 hours ago
-
@LeSuisse
accepted
3 hours ago
-
@LeSuisse
published on GitHub
3 hours ago
WordPress WP Statistics plugin <= 14.16.6 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics allows DOM-Based XSS.
This issue affects WP Statistics: from n/a through 14.16.6.
Permalink
CVE-2026-10157
5.5 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): Low (L)
-
Vulnerable System Impact Integrity (VI): Low (L)
-
Vulnerable System Impact Availability (VA): Low (L)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Exploit Maturity (E): POC (P)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
-
Modified Vulnerable System Impact Integrity (MVI): Low (L)
-
Modified Vulnerable System Impact Availability (MVA): Low (L)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
updated
3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
7 hours ago
-
@LeSuisse
ignored
4 references
3 hours ago
-
@LeSuisse
ignored
package open5gs-webui
3 hours ago
-
@LeSuisse
accepted
3 hours ago
-
@LeSuisse
published on GitHub
3 hours ago
Open5GS NGAP PathSwitchRequest Message ngap-handler.c improper authentication
A vulnerability was identified in Open5GS up to 2.7.6. This impacts an unknown function of the file src/amf/ngap-handler.c of the component NGAP PathSwitchRequest Message Handler. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The identifier of the patch is a188e36b1741ffc2252133f59b1bda4f14d3cb5c. It is suggested to install a patch to address this issue.
Affected products
Open5GS
-
==2.7.0
-
==2.7.5
-
==2.7.6
-
==2.7.3
-
==2.7.1
-
==2.7.4
-
==2.7.2
Matching in nixpkgs
4G/5G core network components
-
-
-
nixos-25.11-small
2.7.7
-
nixpkgs-25.11-darwin
2.7.7
Ignored packages (1)
4G/5G core network components
-
-
-
nixos-25.11-small
2.7.7
-
nixpkgs-25.11-darwin
2.7.7
Permalink
CVE-2026-10232
1.9 LOW
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): Low (L)
-
Vulnerable System Impact Integrity (VI): Low (L)
-
Vulnerable System Impact Availability (VA): Low (L)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Exploit Maturity (E): POC (P)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
-
Modified Vulnerable System Impact Integrity (MVI): Low (L)
-
Modified Vulnerable System Impact Availability (MVA): Low (L)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
updated
3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
7 hours ago
-
@LeSuisse
ignored
4 references
3 hours ago
-
@LeSuisse
accepted
3 hours ago
-
@LeSuisse
published on GitHub
3 hours ago
Assimp ASE File scene.cpp ~aiNode use after free
A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of the file scene.cpp of the component ASE File Parser. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project tagged the reported issue as bug.
Affected products
Assimp
-
==6.0.3
-
==6.0.4
-
==6.0.2
-
==6.0.1
-
==6.0.0
Matching in nixpkgs
Library to import various 3D model formats
-
-
-
nixos-25.11-small
6.0.2
-
nixpkgs-25.11-darwin
6.0.2