Nixpkgs security tracker

Login with GitHub

Suggestions search

With package: cloudflare-dyndns

Found 1 matching suggestions

View:
Compact
Detailed
Permalink CVE-2026-26993
4.6 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 3 months ago Activity log
  • Created suggestion
Flare has XSS vulnerability in Raw File Preview

Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Versions 1.7.0 and below allow users to upload files without proper content validation or sanitization. By embedding malicious JavaScript within an SVG (or other active content formats such as HTML or XML), an attacker can achieve script execution in the context of the application's origin when a victim views the file in “raw” mode. This results in a stored Cross-Site Scripting (XSS) vulnerability that can be exploited to exfiltrate user data. This issue has been fixed in version 1.7.1.

Affected products

Flare
  • ==1.7.1

Matching in nixpkgs

pkgs.flare

Fantasy action RPG using the FLARE engine

  • nixos-unstable 1.14
    • nixpkgs-unstable 1.14
    • nixos-unstable-small 1.14
  • nixos-25.11 1.14
    • nixos-25.11-small 1.14
    • nixpkgs-25.11-darwin 1.14

pkgs.photoflare

Cross-platform image editor with a powerful features and a very friendly graphical user interface

pkgs.flare-floss

Automatically extract obfuscated strings from malware

pkgs.gotlsaflare

Update TLSA DANE records on cloudflare from x509 certificates

pkgs.cloudflare-dyndns

CloudFlare Dynamic DNS client

  • nixos-unstable 5.4
    • nixpkgs-unstable 5.4
    • nixos-unstable-small 5.4
  • nixos-25.11 5.4
    • nixos-25.11-small 5.4
    • nixpkgs-25.11-darwin 5.4

Package maintainers