Nixpkgs Security Tracker

Login with GitHub

Automatically generated suggestions

to queue a suggestion for refinement.

to remove a suggestion from the queue.

created 2 hours ago
WordPress Vocal theme <= 1.12 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Vocal vocal allows PHP Local File Inclusion.This issue affects Vocal: from n/a through <= 1.12.

Affected products

vocal
  • =<<= 1.12

Matching in nixpkgs

pkgs.typstPackages.unequivocal-ams_0_1_0

An AMS-style paper template to publish at conferences and journals for mathematicians

pkgs.typstPackages.unequivocal-ams_0_1_1

An AMS-style paper template to publish at conferences and journals for mathematicians

pkgs.typstPackages.unequivocal-ams_0_1_2

An AMS-style paper template to publish at conferences and journals for mathematicians

Package maintainers: 1

created 2 hours ago
WordPress Health Check & Troubleshooting plugin <= 1.7.1 - Path Traversal vulnerability

Path Traversal: '.../...//' vulnerability in WordPress.org Health Check & Troubleshooting health-check allows Path Traversal.This issue affects Health Check & Troubleshooting: from n/a through <= 1.7.1.

Affected products

health-check
  • =<<= 1.7.1

Matching in nixpkgs

pkgs.python312Packages.django-health-check

Pluggable app that runs a full check on the deployment

pkgs.python313Packages.django-health-check

Pluggable app that runs a full check on the deployment

pkgs.rubyPackages_3_1.github-pages-health-check

None

pkgs.rubyPackages_3_2.github-pages-health-check

None

pkgs.rubyPackages_3_5.github-pages-health-check

None

Package maintainers: 4

created 2 hours ago
WordPress Panda theme <= 1.21 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Panda panda allows PHP Local File Inclusion.This issue affects Panda: from n/a through <= 1.21.

Affected products

panda
  • =<<= 1.21

Matching in nixpkgs

pkgs.python312Packages.pandas

Powerful data structures for data analysis, time series, and statistics

pkgs.python313Packages.pandas

Powerful data structures for data analysis, time series, and statistics

pkgs.python312Packages.biopandas

Working with molecular structures in pandas DataFrames

pkgs.python312Packages.geopandas

Python geospatial data analysis framework

pkgs.python312Packages.pandantic

Module to enriche the Pydantic BaseModel class

pkgs.python313Packages.biopandas

Working with molecular structures in pandas DataFrames

pkgs.python313Packages.geopandas

Python geospatial data analysis framework

pkgs.python313Packages.pandantic

Module to enriche the Pydantic BaseModel class

pkgs.python312Packages.pint-pandas

Pandas support for pint

pkgs.python313Packages.pint-pandas

Pandas support for pint

pkgs.python312Packages.netdata-pandas

A helper library to pull data from the netdata REST API into a pandas dataframe.

pkgs.python313Packages.netdata-pandas

A helper library to pull data from the netdata REST API into a pandas dataframe.

pkgs.python312Packages.geoarrow-pandas

Python implementation of the GeoArrow specification

pkgs.python313Packages.geoarrow-pandas

Python implementation of the GeoArrow specification

pkgs.pkgsRocm.python3Packages.pandantic

Module to enriche the Pydantic BaseModel class

pkgs.python312Packages.prometheus-pandas

Pandas integration for Prometheus

pkgs.python313Packages.prometheus-pandas

Pandas integration for Prometheus

Package maintainers: 19

created 2 hours ago
WordPress ITok theme <= 1.1.42 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme ITok itok.This issue affects ITok: from n/a through <= 1.1.42.

Affected products

itok
  • =<<= 1.1.42

Matching in nixpkgs

pkgs.scitokens-cpp

A C++ implementation of the SciTokens library with a C library interface

pkgs.python312Packages.auditok

Audio Activity Detection tool that can process online data as well as audio files

pkgs.python313Packages.auditok

Audio Activity Detection tool that can process online data as well as audio files

pkgs.python312Packages.pypitoken

Library for generating and manipulating PyPI tokens

pkgs.python313Packages.pypitoken

Library for generating and manipulating PyPI tokens

Package maintainers: 2

created 2 hours ago
WordPress Smash theme <= 1.7 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Smash smash allows PHP Local File Inclusion.This issue affects Smash: from n/a through <= 1.7.

Affected products

smash
  • =<<= 1.7

Matching in nixpkgs

pkgs.git-smash

Smash staged changes into previous commits to support your Git workflow, pull request and feature branch maintenance

Package maintainers: 1

created 2 hours ago
Incorrect security UI in Split View in Google Chrome prior …

Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

Affected products

Chrome
  • <144.0.7559.59

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.05 -
    • nixos-25.05-small
    • nixpkgs-25.05-darwin

pkgs.chrome-export

Scripts to save Google Chrome's bookmarks and history as HTML bookmarks files

pkgs.go-chromecast

CLI for Google Chromecast, Home devices and Cast Groups

pkgs.chrome-token-signing

Chrome and Firefox extension for signing with your eID on the web

pkgs.curl-impersonate-chrome

Special build of curl that can impersonate Chrome & Firefox

pkgs.electron-chromedriver_33

WebDriver server for running Selenium tests on Chrome

pkgs.electron-chromedriver_34

WebDriver server for running Selenium tests on Chrome

pkgs.electron-chromedriver_35

WebDriver server for running Selenium tests on Chrome

pkgs.ocamlPackages.chrome-trace

Chrome trace event generation library

pkgs.python312Packages.pychromecast

Library for Python to communicate with the Google Chromecast

pkgs.python313Packages.pychromecast

Library for Python to communicate with the Google Chromecast

pkgs.python312Packages.undetected-chromedriver

Python library for the custom Selenium ChromeDriver that passes all bot mitigation systems

pkgs.python313Packages.undetected-chromedriver

Python library for the custom Selenium ChromeDriver that passes all bot mitigation systems

pkgs.grafanaPlugins.ventura-psychrometric-panel

Grafana plugin to display air conditions on a psychrometric chart

created 2 hours ago
WordPress Basil theme <= 1.3.12 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Basil basil allows PHP Local File Inclusion.This issue affects Basil: from n/a through <= 1.3.12.

Affected products

basil
  • =<<= 1.3.12

Matching in nixpkgs

pkgs.basilk

Terminal User Interface (TUI) to manage your tasks with minimal kanban logic

pkgs.typstPackages.dmi-basilea-thesis_0_1_0

A thesis template for the dmi at the university of basel

pkgs.typstPackages.dmi-basilea-thesis_0_1_1

A thesis template for the dmi at the university of basel

Package maintainers: 3

created 2 hours ago
pypdf manipulated LZWDecode streams can exhaust RAM

pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability can craft a PDF which leads to a memory usage of up to 1 GB per stream. This requires parsing the content stream of a page using the LZWDecode filter. This issue has been patched in version 6.4.0.

Affected products

pypdf
  • ==< 6.4.0

Matching in nixpkgs

pkgs.python312Packages.pypdf

Pure-python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files

pkgs.python313Packages.pypdf

Pure-python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files

Package maintainers: 5

created 2 hours ago
Folding email comments of unfoldable characters doesn't preserve parenthesis

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.

Affected products

CPython
  • <3.15.0

Matching in nixpkgs

Package maintainers: 1

created 2 hours ago
WordPress Athos theme <= 1.9 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Athos athos allows PHP Local File Inclusion.This issue affects Athos: from n/a through <= 1.9.

Affected products

athos
  • =<<= 1.9

Matching in nixpkgs

pkgs.python312Packages.pathos

Parallel graph management and execution in heterogeneous computing

pkgs.python313Packages.pathos

Parallel graph management and execution in heterogeneous computing