Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestion detail

Untriaged
Permalink CVE-2026-89151
3.5 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 1 week, 1 day ago Activity log
  • Created suggestion
Forgejo before 16.0.4 allows use of restricted API tokens for …

Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.

Affected products

Forgejo
  • <15.0.8
  • <16.0.4

Matching in nixpkgs

pkgs.forgejo

Self-hosted lightweight software forge

  • nixos-unstable -
  • nixos-26.05 -

pkgs.forgejo-cli

CLI application for interacting with Forgejo

  • nixos-unstable -
    • nixos-unstable-small 0.6.0
  • nixos-26.05 -
    • nixos-26.05-small 0.6.0

pkgs.forgejo-lts

Self-hosted lightweight software forge

  • nixos-unstable -
  • nixos-26.05 -

pkgs.forgejo-mcp

Model Context Protocol (MCP) server for interacting with the Forgejo REST API

  • nixos-unstable -
  • nixos-26.05 -

pkgs.forgejo-runner

Runner for Forgejo based on act

  • nixos-unstable -
  • nixos-26.05 -