Stored Cross-Site Scripting (XSS) in LUNA from Luna Imaging
Stored Cross-Site Scripting (XSS) vulnerability type in LUNA software v7.5.5.6. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by inyecting a malicious payload through the 'Edit Batch Name' function. THe payload is stored by the application and subsequently displayed without proper sanitization when other users access it. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.
Affected products
- ==7.5.5.6
Matching in nixpkgs
pkgs.lunar
Defacto app for controlling monitors
pkgs.lunacy
Free design software that keeps your flow with AI tools and built-in graphics
pkgs.lunarml
Standard ML compiler that produces Lua/JavaScript
pkgs.lunasvg
SVG rendering and manipulation library in C++
pkgs.lunatic
Erlang inspired runtime for WebAssembly
-
nixos-unstable 0.13.2-unstable-2025-03-29
- nixpkgs-unstable 0.13.2-unstable-2025-03-29
- nixos-unstable-small 0.13.2-unstable-2025-03-29
-
nixos-25.11 -
- nixos-25.11-small 0.13.2-unstable-2025-03-29
- nixpkgs-25.11-darwin 0.13.2-unstable-2025-03-29
-
nixos-25.05 0.13.2-unstable-2025-03-29
- nixos-25.05-small 0.13.2-unstable-2025-03-29
- nixpkgs-25.05-darwin 0.13.2-unstable-2025-03-29
pkgs.lunarvim
IDE layer for Neovim
pkgs.lunatask
All-in-one encrypted todo list, notebook, habit and mood tracker, pomodoro timer, and journaling app
pkgs.lunar-client
Free Minecraft client with mods, cosmetics, and performance boost
pkgs.vulkan-tools-lunarg
LunarG Vulkan Tools and Utilities
pkgs.python312Packages.luna-soc
Amaranth HDL library for building USB-capable SoC designs
pkgs.python312Packages.luna-usb
Amaranth HDL framework for monitoring, hacking, and developing USB devices
pkgs.python313Packages.luna-soc
Amaranth HDL library for building USB-capable SoC designs
pkgs.python313Packages.luna-usb
Amaranth HDL framework for monitoring, hacking, and developing USB devices
pkgs.python314Packages.luna-soc
Amaranth HDL library for building USB-capable SoC designs
pkgs.python314Packages.luna-usb
Amaranth HDL framework for monitoring, hacking, and developing USB devices
pkgs.gnomeExtensions.lunar-calendar
Display Chinese Lunar Calendar in panel
pkgs.python312Packages.lunarcalendar
Lunar-Solar Converter, containing a number of lunar and solar festivals in China
pkgs.python313Packages.lunarcalendar
Lunar-Solar Converter, containing a number of lunar and solar festivals in China
pkgs.python314Packages.lunarcalendar
Lunar-Solar Converter, containing a number of lunar and solar festivals in China
pkgs.home-assistant-component-tests.lunatone
Open source home automation that puts local control and privacy first
pkgs.python312Packages.korean-lunar-calendar
Library to convert Korean lunar-calendar to Gregorian calendar
pkgs.python313Packages.korean-lunar-calendar
Library to convert Korean lunar-calendar to Gregorian calendar
pkgs.python314Packages.korean-lunar-calendar
Library to convert Korean lunar-calendar to Gregorian calendar
pkgs.gnomeExtensions.luna-moon-phase-indicator
Luna is a simple GNOME Shell extension that displays the current moon phase directly in your top bar. With beautiful custom icons and real-time updates, Luna helps you stay attuned to lunar cycles throughout your day.
pkgs.python312Packages.lunatone-rest-api-client
Client library for accessing the Lunatone REST API
pkgs.python313Packages.lunatone-rest-api-client
Client library for accessing the Lunatone REST API
pkgs.python314Packages.lunatone-rest-api-client
Client library for accessing the Lunatone REST API
Package maintainers
-
@honnip Jung seungwoo <me@honnip.page>
-
@eliandoran Elian Doran <contact@eliandoran.me>
-
@luftmensch-luftmensch Valentino Bocchetti <valentinobocchetti59@gmail.com>
-
@Technical27 Aamaruvi Yogamani
-
@ratsclub Victor Freire <victor@freire.dev.br>
-
@toastal toastal <toastal+nix@posteo.net>
-
@ProminentRetail Jake Park <me@jakepark.me>
-
@lebensterben Lucius Hu
-
@hatch01 Eymeric Dechelette <hatchchien@protonmail.com>
-
@zi3m5f zi3m5f <k7n3o3a6f@mozmail.com>
-
@figsoda figsoda <figsoda@pm.me>
-
@risicle Robert Scott <code@humanleg.org.uk>
-
@TomaSajt TomaSajt
-
@delafthi Thierry Delafontaine <delafthi@pm.me>
-
@carlossless Karolis Stasaitis <contact@carlossless.io>
-
@dotlambda Robert Schütz <rschuetz17@gmail.com>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@mweinelt Martin Weinelt <hexa@darmstadt.ccc.de>