Nixpkgs security tracker

Login with GitHub

Details of issue NIXPKGS-2026-0008

NIXPKGS-2026-0008
published on
updated 2 months, 4 weeks ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package pretix-banktool
  • @LeSuisse removed maintainer @mweinelt
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Insecure direct object reference

Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only.

Affected products

pretix
  • <2025.11.0
  • <2025.8.0
  • <2025.9.0
  • <2025.10.0

Matching in nixpkgs

pkgs.pretix

Ticketing software that cares about your event—all the way

Package maintainers

Ignored maintainers (1)
https://github.com/NixOS/nixpkgs/pull/472420 (Unstable)
https://github.com/NixOS/nixpkgs/pull/472424 (25.11)