Nixpkgs Security Tracker

Login with GitHub

Automatically generated suggestions

to queue a suggestion for refinement.

to remove a suggestion from the queue.

created 1 day, 21 hours ago
ImageMagick vulnerable to Release of Invalid Pointer in BilateralBlur when memory allocation fails

ImageMagick is free and open-source software used for editing and manipulating digital images. The BilateralBlurImage method will allocate a set of double buffers inside AcquireBilateralTLS. But, in versions prior to 7.1.2-13, the last element in the set is not properly initialized. This will result in a release of an invalid pointer inside DestroyBilateralTLS when the memory allocation fails. Version 7.1.2-13 contains a patch for the issue.

Affected products

ImageMagick
  • ==< 7.1.2-13

Matching in nixpkgs

pkgs.graphicsmagick-imagemagick-compat

Repack of GraphicsMagick that provides compatibility with ImageMagick interfaces

pkgs.tests.pkg-config.defaultPkgConfigPackages.MagickWand

Test whether imagemagick-7.1.2-8 exposes pkg-config modules MagickWand

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.05 -
    • nixos-25.05-small
    • nixpkgs-25.05-darwin

pkgs.tests.pkg-config.defaultPkgConfigPackages.ImageMagick

Test whether imagemagick-7.1.2-8 exposes pkg-config modules ImageMagick

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.05 -
    • nixos-25.05-small
    • nixpkgs-25.05-darwin

Package maintainers: 3

created 1 day, 21 hours ago
Stored Cross-Site Scripting (XSS) in Sesame web application

Stored Cross-Site Scripting (XSS) vulnerability in Sesame web application, due to the fact that uploaded SVG images are not properly sanitized. This allows attackers to embed malicious scripts in SVG files by sending a POST request using the 'logo' parameter in '/api/v3/companies/<ID>/logo', which are then stored on the server and executed in the context of any user who accesses the compromised resource.

Affected products

Sesame
  • ==all versions

Matching in nixpkgs

pkgs.python312Packages.django-sesame

URLs with authentication tokens for automatic login

pkgs.python313Packages.django-sesame

URLs with authentication tokens for automatic login

Package maintainers: 1

created 1 day, 22 hours ago
WordPress Echo theme <= 1.15.0 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Echo echo allows PHP Local File Inclusion.This issue affects Echo: from n/a through <= 1.15.0.

Affected products

echo
  • =<<= 1.15.0

Matching in nixpkgs

pkgs.vkdevicechooser

Vulkan layer to force a specific device to be used

pkgs.haskellPackages.echo

A cross-platform, cross-console way to handle echoing terminal input

pkgs.python312Packages.llm-echo

Debug plugin for LLM

pkgs.python313Packages.llm-echo

Debug plugin for LLM

pkgs.python312Packages.pycolorecho

Simple Python package for colorized terminal output

pkgs.python313Packages.pycolorecho

Simple Python package for colorized terminal output

pkgs.xdg-desktop-portal-termfilechooser

xdg-desktop-portal backend for choosing files with your favorite file chooser

Package maintainers: 9

created 1 day, 22 hours ago
Out of bounds memory access in V8 in Google Chrome …

Out of bounds memory access in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

Affected products

Chrome
  • <144.0.7559.59

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.05 -
    • nixos-25.05-small
    • nixpkgs-25.05-darwin

pkgs.chrome-export

Scripts to save Google Chrome's bookmarks and history as HTML bookmarks files

pkgs.go-chromecast

CLI for Google Chromecast, Home devices and Cast Groups

pkgs.chrome-token-signing

Chrome and Firefox extension for signing with your eID on the web

pkgs.curl-impersonate-chrome

Special build of curl that can impersonate Chrome & Firefox

pkgs.electron-chromedriver_33

WebDriver server for running Selenium tests on Chrome

pkgs.electron-chromedriver_34

WebDriver server for running Selenium tests on Chrome

pkgs.electron-chromedriver_35

WebDriver server for running Selenium tests on Chrome

pkgs.ocamlPackages.chrome-trace

Chrome trace event generation library

pkgs.python312Packages.pychromecast

Library for Python to communicate with the Google Chromecast

pkgs.python313Packages.pychromecast

Library for Python to communicate with the Google Chromecast

pkgs.python312Packages.undetected-chromedriver

Python library for the custom Selenium ChromeDriver that passes all bot mitigation systems

pkgs.python313Packages.undetected-chromedriver

Python library for the custom Selenium ChromeDriver that passes all bot mitigation systems

pkgs.grafanaPlugins.ventura-psychrometric-panel

Grafana plugin to display air conditions on a psychrometric chart

created 1 day, 22 hours ago
WordPress Saxon - Viral Content Blog & Magazine Marketing WordPress Theme theme <= 1.9.3 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dedalx Saxon - Viral Content Blog & Magazine Marketing WordPress Theme saxon allows PHP Local File Inclusion.This issue affects Saxon - Viral Content Blog & Magazine Marketing WordPress Theme: from n/a through <= 1.9.3.

Affected products

saxon
  • =<<= 1.9.3

Matching in nixpkgs

pkgs.saxonb

Complete and conformant processor of XSLT 2.0, XQuery 1.0, and XPath 2.0

  • nixos-unstable -

pkgs.saxon-he

Processor for XSLT 3.0, XPath 3.1, and XQuery 3.1

  • nixos-unstable -

pkgs.saxonb_8_8

Complete and conformant processor of XSLT 2.0, XQuery 1.0, and XPath 2.0

pkgs.saxon_11-he

Processor for XSLT 3.0, XPath 2.0 and 3.1, and XQuery 3.1

pkgs.saxon_12-he

Processor for XSLT 3.0, XPath 3.1, and XQuery 3.1

Package maintainers: 1

created 1 day, 22 hours ago
Chamilo LMS Legal Consent SocialController.php deleteLegal improper authorization

A security flaw has been discovered in Chamilo LMS up to 2.0.0 Beta 1. This issue affects the function deleteLegal of the file src/CoreBundle/Controller/SocialController.php of the component Legal Consent Handler. Performing a manipulation of the argument userId results in improper authorization. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

LMS
  • ==2.0.0 Beta 1

Matching in nixpkgs

pkgs.python312Packages.calmsize

Take a number of bytes and return a human-readable string

pkgs.python313Packages.calmsize

Take a number of bytes and return a human-readable string

pkgs.tests.testers.runCommand.dns-resolution

None

pkgs.python312Packages.llama-index-llms-ollama

LlamaIndex LLMS Integration for ollama

pkgs.python312Packages.llama-index-llms-openai

LlamaIndex LLMS Integration for OpenAI

pkgs.python313Packages.llama-index-llms-ollama

LlamaIndex LLMS Integration for ollama

pkgs.python313Packages.llama-index-llms-openai

LlamaIndex LLMS Integration for OpenAI

pkgs.python312Packages.llama-index-llms-openai-like

LlamaIndex LLMS Integration for OpenAI like

pkgs.python313Packages.llama-index-llms-openai-like

LlamaIndex LLMS Integration for OpenAI like

pkgs.pkgsRocm.python3Packages.llama-index-llms-ollama

LlamaIndex LLMS Integration for ollama

pkgs.pkgsRocm.python3Packages.llama-index-llms-openai

LlamaIndex LLMS Integration for OpenAI

pkgs.pkgsRocm.python3Packages.llama-index-llms-openai-like

LlamaIndex LLMS Integration for OpenAI like

pkgs.python312Packages.llama-index-multi-modal-llms-openai

LlamaIndex Multi-Modal-Llms Integration for OpenAI

pkgs.python313Packages.llama-index-multi-modal-llms-openai

LlamaIndex Multi-Modal-Llms Integration for OpenAI

pkgs.pkgsRocm.python3Packages.llama-index-multi-modal-llms-openai

LlamaIndex Multi-Modal-Llms Integration for OpenAI

Package maintainers: 7

created 1 day, 22 hours ago
CVE-2026-1245

A code injection vulnerability in the binary-parser library prior to version 2.3.0 allows arbitrary JavaScript code execution when untrusted values are used in parser field names or encoding parameters. The library directly interpolates these values into dynamically generated code without sanitization, enabling attackers to execute arbitrary code in the context of the Node.js process.

Affected products

binary-parser
  • =<2.3.0

Matching in nixpkgs

pkgs.haskellPackages.binary-parsers

Extends binary with parsec/attoparsec style parsing combinators

created 3 days, 22 hours ago
Open Asset Import Library Assimp LWOMaterial.cpp FindUVChannels use after free

A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. Affected by this vulnerability is the function Assimp::LWOImporter::FindUVChannels of the file /src/assimp/code/AssetLib/LWO/LWOMaterial.cpp. Such manipulation leads to use after free. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. This and similar defects are tracked and handled via issue #6128.

Affected products

Assimp
  • ==6.0.2
  • ==6.0.0
  • ==6.0.1

Matching in nixpkgs

Package maintainers: 1

created 3 days, 22 hours ago
raysan5 raylib rtext.c LoadFontData integer overflow

A vulnerability was identified in raysan5 raylib up to 909f040. Affected by this issue is the function LoadFontData of the file src/rtext.c. The manipulation leads to integer overflow. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The identifier of the patch is 5a3391fdce046bc5473e52afbd835dd2dc127146. It is suggested to install a patch to address this issue.

Affected products

raylib
  • ==909f040

Matching in nixpkgs

pkgs.raylib

Simple and easy-to-use library to enjoy videogames programming

pkgs.ocamlPackages.raylib

OCaml bindings for Raylib (5.0.0)

Package maintainers: 4

created 2 months ago
Xorg: xwayland: use-after-free in xkb client resource removal

A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.

Affected products

tigervnc
  • *
xwayland
  • <24.1.9
xorg-x11-server
  • *
xorg-x11-server-Xwayland
  • *

Matching in nixpkgs