Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: discord-gamesdk

Found 3 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2026-100583
5.3 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 day, 11 hours ago Activity log
  • Created suggestion
OpenClaw Discord before 2026.7.1 Authorization Bypass

OpenClaw Discord versions before 2026.7.1 contain an authorization bypass vulnerability in guild metadata read actions that allows lower-trust senders to retrieve information excluded by channel allowlists. Attackers can bypass the configured Discord read-target policy to access guild metadata from servers or channels outside the operator's allowlist.

Affected products

discord
  • ==2026.7.1
  • <2026.7.1

Matching in nixpkgs

pkgs.discord

All-in-one cross-platform voice and text chat for gamers

  • nixos-unstable -
  • nixos-26.05 -

pkgs.discord-sh

Write-only command-line Discord webhook integration written in 100% Bash script

  • nixos-unstable -
    • nixos-unstable-small 2.0.1
  • nixos-26.05 -
    • nixos-26.05-small 2.0.1

pkgs.discord-ptb

All-in-one cross-platform voice and text chat for gamers

  • nixos-unstable -
  • nixos-26.05 -

pkgs.discord-rpc

Official library to interface with the Discord client

  • nixos-unstable -
    • nixos-unstable-small 3.4.0
  • nixos-26.05 -
    • nixos-26.05-small 3.4.0

pkgs.discord-canary

All-in-one cross-platform voice and text chat for gamers

  • nixos-unstable -
  • nixos-26.05 -

pkgs.bitlbee-discord

Bitlbee plugin for Discord

  • nixos-unstable -
    • nixos-unstable-small 0.4.3
  • nixos-26.05 -
    • nixos-26.05-small 0.4.3

pkgs.discord-gamesdk

Library to allow other programs to interact with the Discord desktop application

  • nixos-unstable -
    • nixos-unstable-small 3.2.1
  • nixos-26.05 -
    • nixos-26.05-small 3.2.1

pkgs.mautrix-discord

Matrix-Discord puppeting bridge

  • nixos-unstable -
    • nixos-unstable-small 0.7.7
  • nixos-26.05 -
    • nixos-26.05-small 0.7.6

pkgs.mpd-discord-rpc

Rust application which displays your currently playing song / album / artist from MPD in Discord using Rich Presence

  • nixos-unstable -
  • nixos-26.05 -

pkgs.betterdiscordctl

Utility for managing BetterDiscord on Linux

  • nixos-unstable -
    • nixos-unstable-small 2.1.0
  • nixos-26.05 -
    • nixos-26.05-small 2.1.0

pkgs.music-discord-rpc

Cross-platform Discord rich presence for music with album cover and progress bar support

  • nixos-unstable -
    • nixos-unstable-small 0.7.0
  • nixos-26.05 -
    • nixos-26.05-small 0.7.0

pkgs.mpvScripts.mpv-discord

Cross-platform Discord Rich Presence integration for mpv with no external dependencies

  • nixos-unstable -
    • nixos-unstable-small 1.6.1
  • nixos-26.05 -
    • nixos-26.05-small 1.6.1
Untriaged
Permalink CVE-2026-100526
6.0 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 day, 11 hours ago Activity log
  • Created suggestion
Vulnerability in discord

OpenClaw's Discord integration (npm package @openclaw/discord) before version 2026.9.3 could lose the sender-scoped media policy in the emoji and sticker upload actions before loading a local file. A sender permitted to invoke those actions could cause OpenClaw to read a host path that the same sender's configured media roots would otherwise reject, placing bytes from an out-of-policy local file into an outbound emoji or sticker upload. Exploitation requires access to the guild asset action and knowledge or derivation of a useful local path; the issue does not permit unrestricted filesystem browsing or code execution. The issue is fixed in @openclaw/discord 2026.9.3.

Affected products

discord
  • <2026.9.3
  • ==2026.9.3

Matching in nixpkgs

pkgs.discord

All-in-one cross-platform voice and text chat for gamers

  • nixos-unstable -
  • nixos-26.05 -

pkgs.discord-sh

Write-only command-line Discord webhook integration written in 100% Bash script

  • nixos-unstable -
    • nixos-unstable-small 2.0.1
  • nixos-26.05 -
    • nixos-26.05-small 2.0.1

pkgs.discord-ptb

All-in-one cross-platform voice and text chat for gamers

  • nixos-unstable -
  • nixos-26.05 -

pkgs.discord-rpc

Official library to interface with the Discord client

  • nixos-unstable -
    • nixos-unstable-small 3.4.0
  • nixos-26.05 -
    • nixos-26.05-small 3.4.0

pkgs.discord-canary

All-in-one cross-platform voice and text chat for gamers

  • nixos-unstable -
  • nixos-26.05 -

pkgs.bitlbee-discord

Bitlbee plugin for Discord

  • nixos-unstable -
    • nixos-unstable-small 0.4.3
  • nixos-26.05 -
    • nixos-26.05-small 0.4.3

pkgs.discord-gamesdk

Library to allow other programs to interact with the Discord desktop application

  • nixos-unstable -
    • nixos-unstable-small 3.2.1
  • nixos-26.05 -
    • nixos-26.05-small 3.2.1

pkgs.mautrix-discord

Matrix-Discord puppeting bridge

  • nixos-unstable -
    • nixos-unstable-small 0.7.7
  • nixos-26.05 -
    • nixos-26.05-small 0.7.6

pkgs.mpd-discord-rpc

Rust application which displays your currently playing song / album / artist from MPD in Discord using Rich Presence

  • nixos-unstable -
  • nixos-26.05 -

pkgs.betterdiscordctl

Utility for managing BetterDiscord on Linux

  • nixos-unstable -
    • nixos-unstable-small 2.1.0
  • nixos-26.05 -
    • nixos-26.05-small 2.1.0

pkgs.music-discord-rpc

Cross-platform Discord rich presence for music with album cover and progress bar support

  • nixos-unstable -
    • nixos-unstable-small 0.7.0
  • nixos-26.05 -
    • nixos-26.05-small 0.7.0

pkgs.mpvScripts.mpv-discord

Cross-platform Discord Rich Presence integration for mpv with no external dependencies

  • nixos-unstable -
    • nixos-unstable-small 1.6.1
  • nixos-26.05 -
    • nixos-26.05-small 1.6.1
Untriaged
Permalink CVE-2026-8919
7.2 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Passive (P)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): Low (L)
  • Subsequent System Impact Integrity (SI): Low (L)
  • Subsequent System Impact Availability (SA): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Passive (P)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Low (L)
  • Modified Subsequent System Impact Integrity (MSI): Low (L)
  • Modified Subsequent System Impact Availability (MSA): Low (L)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 months, 1 week ago Activity log
  • Created suggestion
Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK …

Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application’s local service endpoint. This can result in information disclosure or data tampering, may cause GameSDK to become unavailable, and may also enable access to the victim’s information on other services. Refer to the ' Security Update for ASUS GameSDK  ' section on the ASUS Security Advisory for more information.

Affected products

GameSDK
  • =<V1.0.5

Matching in nixpkgs

pkgs.discord-gamesdk

Library to allow other programs to interact with the Discord desktop application

  • nixos-unstable -
    • nixos-unstable-small 3.2.1
  • nixos-26.05 -
    • nixos-26.05-small 3.2.1

Package maintainers