Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: discordchatexporter-cli

Found 5 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2026-100583
5.3 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 day, 15 hours ago Activity log
  • Created suggestion
OpenClaw Discord before 2026.7.1 Authorization Bypass

OpenClaw Discord versions before 2026.7.1 contain an authorization bypass vulnerability in guild metadata read actions that allows lower-trust senders to retrieve information excluded by channel allowlists. Attackers can bypass the configured Discord read-target policy to access guild metadata from servers or channels outside the operator's allowlist.

Affected products

discord
  • ==2026.7.1
  • <2026.7.1

Matching in nixpkgs

pkgs.discord

All-in-one cross-platform voice and text chat for gamers

  • nixos-unstable -
  • nixos-26.05 -

pkgs.discord-sh

Write-only command-line Discord webhook integration written in 100% Bash script

  • nixos-unstable -
    • nixos-unstable-small 2.0.1
  • nixos-26.05 -
    • nixos-26.05-small 2.0.1

pkgs.discord-ptb

All-in-one cross-platform voice and text chat for gamers

  • nixos-unstable -
  • nixos-26.05 -

pkgs.discord-rpc

Official library to interface with the Discord client

  • nixos-unstable -
    • nixos-unstable-small 3.4.0
  • nixos-26.05 -
    • nixos-26.05-small 3.4.0

pkgs.discord-canary

All-in-one cross-platform voice and text chat for gamers

  • nixos-unstable -
  • nixos-26.05 -

pkgs.bitlbee-discord

Bitlbee plugin for Discord

  • nixos-unstable -
    • nixos-unstable-small 0.4.3
  • nixos-26.05 -
    • nixos-26.05-small 0.4.3

pkgs.discord-gamesdk

Library to allow other programs to interact with the Discord desktop application

  • nixos-unstable -
    • nixos-unstable-small 3.2.1
  • nixos-26.05 -
    • nixos-26.05-small 3.2.1

pkgs.mautrix-discord

Matrix-Discord puppeting bridge

  • nixos-unstable -
    • nixos-unstable-small 0.7.7
  • nixos-26.05 -
    • nixos-26.05-small 0.7.6

pkgs.mpd-discord-rpc

Rust application which displays your currently playing song / album / artist from MPD in Discord using Rich Presence

  • nixos-unstable -
  • nixos-26.05 -

pkgs.betterdiscordctl

Utility for managing BetterDiscord on Linux

  • nixos-unstable -
    • nixos-unstable-small 2.1.0
  • nixos-26.05 -
    • nixos-26.05-small 2.1.0

pkgs.music-discord-rpc

Cross-platform Discord rich presence for music with album cover and progress bar support

  • nixos-unstable -
    • nixos-unstable-small 0.7.0
  • nixos-26.05 -
    • nixos-26.05-small 0.7.0

pkgs.mpvScripts.mpv-discord

Cross-platform Discord Rich Presence integration for mpv with no external dependencies

  • nixos-unstable -
    • nixos-unstable-small 1.6.1
  • nixos-26.05 -
    • nixos-26.05-small 1.6.1
Untriaged
Permalink CVE-2026-100526
6.0 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 day, 15 hours ago Activity log
  • Created suggestion
Vulnerability in discord

OpenClaw's Discord integration (npm package @openclaw/discord) before version 2026.9.3 could lose the sender-scoped media policy in the emoji and sticker upload actions before loading a local file. A sender permitted to invoke those actions could cause OpenClaw to read a host path that the same sender's configured media roots would otherwise reject, placing bytes from an out-of-policy local file into an outbound emoji or sticker upload. Exploitation requires access to the guild asset action and knowledge or derivation of a useful local path; the issue does not permit unrestricted filesystem browsing or code execution. The issue is fixed in @openclaw/discord 2026.9.3.

Affected products

discord
  • <2026.9.3
  • ==2026.9.3

Matching in nixpkgs

pkgs.discord

All-in-one cross-platform voice and text chat for gamers

  • nixos-unstable -
  • nixos-26.05 -

pkgs.discord-sh

Write-only command-line Discord webhook integration written in 100% Bash script

  • nixos-unstable -
    • nixos-unstable-small 2.0.1
  • nixos-26.05 -
    • nixos-26.05-small 2.0.1

pkgs.discord-ptb

All-in-one cross-platform voice and text chat for gamers

  • nixos-unstable -
  • nixos-26.05 -

pkgs.discord-rpc

Official library to interface with the Discord client

  • nixos-unstable -
    • nixos-unstable-small 3.4.0
  • nixos-26.05 -
    • nixos-26.05-small 3.4.0

pkgs.discord-canary

All-in-one cross-platform voice and text chat for gamers

  • nixos-unstable -
  • nixos-26.05 -

pkgs.bitlbee-discord

Bitlbee plugin for Discord

  • nixos-unstable -
    • nixos-unstable-small 0.4.3
  • nixos-26.05 -
    • nixos-26.05-small 0.4.3

pkgs.discord-gamesdk

Library to allow other programs to interact with the Discord desktop application

  • nixos-unstable -
    • nixos-unstable-small 3.2.1
  • nixos-26.05 -
    • nixos-26.05-small 3.2.1

pkgs.mautrix-discord

Matrix-Discord puppeting bridge

  • nixos-unstable -
    • nixos-unstable-small 0.7.7
  • nixos-26.05 -
    • nixos-26.05-small 0.7.6

pkgs.mpd-discord-rpc

Rust application which displays your currently playing song / album / artist from MPD in Discord using Rich Presence

  • nixos-unstable -
  • nixos-26.05 -

pkgs.betterdiscordctl

Utility for managing BetterDiscord on Linux

  • nixos-unstable -
    • nixos-unstable-small 2.1.0
  • nixos-26.05 -
    • nixos-26.05-small 2.1.0

pkgs.music-discord-rpc

Cross-platform Discord rich presence for music with album cover and progress bar support

  • nixos-unstable -
    • nixos-unstable-small 0.7.0
  • nixos-26.05 -
    • nixos-26.05-small 0.7.0

pkgs.mpvScripts.mpv-discord

Cross-platform Discord Rich Presence integration for mpv with no external dependencies

  • nixos-unstable -
    • nixos-unstable-small 1.6.1
  • nixos-26.05 -
    • nixos-26.05-small 1.6.1
Untriaged
Permalink CVE-2026-97326
5.5 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Exploit Maturity (E): POC (P)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
created 3 days, 15 hours ago Activity log
  • Created suggestion
songxinjianqwe Chat chat-server ChatServer.java server-side request forgery

A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d. Affected by this issue is some unknown functionality of the file chat-server/src/main/java/cn/sinjinsong/chat/server/ChatServer.java of the component chat-server. This manipulation causes server-side request forgery. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

Chat
  • ==ac63d25297079eed5e4ba7e88d3b7a032637150d

Matching in nixpkgs

pkgs.chatd

Chat with your documents using local AI

  • nixos-unstable -
    • nixos-unstable-small 1.1.2
  • nixos-26.05 -
    • nixos-26.05-small 1.1.2

pkgs.kchat

Instant messaging service part of Infomaniak KSuite

  • nixos-unstable -
    • nixos-unstable-small 3.5.1
  • nixos-26.05 -
    • nixos-26.05-small 3.3.3

pkgs.nchat

Terminal-based chat client with support for Telegram and WhatsApp

  • nixos-unstable -
  • nixos-26.05 -

pkgs.aichat

Use GPT-4(V), Gemini, LocalAI, Ollama and other LLMs in the terminal

  • nixos-unstable -
  • nixos-26.05 -

pkgs.chatty

XMPP and SMS messaging via libpurple and ModemManager

  • nixos-unstable -
    • nixos-unstable-small 0.8.9
  • nixos-26.05 -
    • nixos-26.05-small 0.8.9

pkgs.ttchat

Connect to a Twitch channel's chat from your terminal

  • nixos-unstable -
  • nixos-26.05 -

pkgs.wechat

Messaging and calling app

  • nixos-unstable -
  • nixos-26.05 -

pkgs.weechat

Fast, light and extensible chat client

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ssh-chat

Chat over SSH

  • nixos-unstable -
  • nixos-26.05 -

pkgs.chatblade

CLI Swiss Army Knife for ChatGPT

  • nixos-unstable -
    • nixos-unstable-small 0.7.0
  • nixos-26.05 -
    • nixos-26.05-small 0.7.0

pkgs.librechat

Open-source app for all your AI conversations, fully customizable and compatible with any AI provider

  • nixos-unstable -
    • nixos-unstable-small 0.8.7
  • nixos-26.05 -
    • nixos-26.05-small 0.8.6

pkgs.aider-chat

AI pair programming in your terminal

  • nixos-unstable -
  • nixos-26.05 -

pkgs.fluffychat

Chat with your friends (matrix client)

  • nixos-unstable -
    • nixos-unstable-small 2.9.4
  • nixos-26.05 -
    • nixos-26.05-small 2.6.0

pkgs.chatgpt-cli

Interactive CLI for ChatGPT

  • nixos-unstable -
    • nixos-unstable-small 1.3.5
  • nixos-26.05 -
    • nixos-26.05-small 1.3.5

pkgs.chatterino2

Chat client for Twitch chat

  • nixos-unstable -
    • nixos-unstable-small 2.5.5
  • nixos-26.05 -
    • nixos-26.05-small 2.5.5

pkgs.chatterino7

Chat client for Twitch chat

  • nixos-unstable -
    • nixos-unstable-small 7.5.5
  • nixos-26.05 -
    • nixos-26.05-small 7.5.5

pkgs.commet-chat

Client for Matrix focused on providing a feature rich experience while maintaining a simple interface

pkgs.libdeltachat

Delta Chat Rust Core library

  • nixos-unstable -
  • nixos-26.05 -

pkgs.libgnunetchat

Library for secure, decentralized chat using GNUnet network services

  • nixos-unstable -
    • nixos-unstable-small 0.6.1
  • nixos-26.05 -
    • nixos-26.05-small 0.6.1

pkgs.arcanechat-tui

Lightweight Delta Chat client

  • nixos-unstable -
  • nixos-26.05 -

pkgs.fluffychat-web

Chat with your friends (matrix client)

  • nixos-unstable -
    • nixos-unstable-small 2.9.4
  • nixos-26.05 -
    • nixos-26.05-small 2.6.0

pkgs.pkgsRocm.chatd

Chat with your documents using local AI

  • nixos-unstable -
    • nixos-unstable-small 1.1.2
  • nixos-26.05 -
    • nixos-26.05-small 1.1.2

pkgs.aider-chat-full

AI pair programming in your terminal

  • nixos-unstable -
  • nixos-26.05 -

pkgs.chatzone-desktop

Ozon corporate messenger

  • nixos-unstable -
    • nixos-unstable-small 5.7.0
  • nixos-26.05 -
    • nixos-26.05-small 5.7.0

pkgs.chatgpt-shell-cli

Simple shell script to use OpenAI's ChatGPT and DALL-E from the terminal. No Python or JS required

  • nixos-unstable -
    • nixos-unstable-small
  • nixos-26.05 -
    • nixos-26.05-small

pkgs.deltachat-desktop

Email-based instant messaging for Desktop

  • nixos-unstable -
  • nixos-26.05 -

pkgs.weechat-unwrapped

Fast, light and extensible chat client

  • nixos-unstable -
  • nixos-26.05 -

pkgs.mautrix-googlechat

Matrix-Google Chat puppeting bridge

  • nixos-unstable -
    • nixos-unstable-small 0.5.2
  • nixos-26.05 -
    • nixos-26.05-small 0.5.2

pkgs.kdePackages.neochat

A client for matrix, the decentralized communication protocol

  • nixos-unstable -
  • nixos-26.05 -

pkgs.weechatScripts.edit

This simple weechat plugin allows you to compose messages in your $EDITOR

  • nixos-unstable -
    • nixos-unstable-small 1.0.2
  • nixos-26.05 -
    • nixos-26.05-small 1.0.2

pkgs.deltachat-rpc-server

Delta Chat RPC server exposing JSON-RPC core API over standard I/O

  • nixos-unstable -
  • nixos-26.05 -

pkgs.reticulum-group-chat

Pure-Go LXMF group-chat hub for the Reticulum network — a single static binary that relays many-to-many encrypted text chat over LoRa, TCP/IP, and mixed meshes. No Python, no third-party RNS library

  • nixos-unstable -

pkgs.weechatScripts.autosort

autosort automatically keeps your buffers sorted and grouped by server

  • nixos-unstable -
    • nixos-unstable-small 3.10
  • nixos-26.05 -
    • nixos-26.05-small 3.10

pkgs.python313Packages.fschat

Open platform for training, serving, and evaluating large language models. Release repo for Vicuna and Chatbot Arena

  • nixos-unstable -
  • nixos-26.05 -

pkgs.python314Packages.fschat

Open platform for training, serving, and evaluating large language models. Release repo for Vicuna and Chatbot Arena

  • nixos-unstable -
  • nixos-26.05 -

pkgs.python313Packages.chatlas

Friendly guide to building LLM chat apps in Python with less effort and more clarity

  • nixos-unstable -
  • nixos-26.05 -

pkgs.python314Packages.chatlas

Friendly guide to building LLM chat apps in Python with less effort and more clarity

  • nixos-unstable -
  • nixos-26.05 -

pkgs.weechatScripts.weechat-go

WeeChat script to quickly jump to different buffers

  • nixos-unstable -
    • nixos-unstable-small 2.7
  • nixos-26.05 -
    • nixos-26.05-small 2.7

pkgs.weechatScripts.weechat-autosort

Autosort is a weechat script to automatically or manually keep your buffers sorted

  • nixos-unstable -
    • nixos-unstable-small 3.9
  • nixos-26.05 -
    • nixos-26.05-small 3.9

pkgs.python313Packages.chat-downloader

Simple tool used to retrieve chat messages from livestreams, videos, clips and past broadcasts

  • nixos-unstable -
    • nixos-unstable-small 0.2.8
  • nixos-26.05 -
    • nixos-26.05-small 0.2.8

pkgs.python314Packages.chat-downloader

Simple tool used to retrieve chat messages from livestreams, videos, clips and past broadcasts

  • nixos-unstable -
    • nixos-unstable-small 0.2.8
  • nixos-26.05 -
    • nixos-26.05-small 0.2.8

pkgs.gnomeExtensions.penguin-ai-chatbot

A GNOME Shell extension that provides a chatbot interface using various LLM providers, including Anthropic, OpenAI, Gemini, and OpenRouter. Features include multiple provider support, customizable models, chat history, customizable appearance, a keyboard shortcut, web search, location (by using the extension, you consent to sharing your location with OpenRouter for AI Tools) and copy-to-clipboard functionality.

  • nixos-unstable -
    • nixos-unstable-small 28
  • nixos-26.05 -
    • nixos-26.05-small 25

Package maintainers

Untriaged
Permalink CVE-2026-54682
8.2 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created suggestion
DiscordChatExporter: Stored XSS in HTML export when markdown formatting is disabled

DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and FormatEmbedMarkdownAsync in DiscordChatExporter.Core/Exporting/MessageGroupTemplate.cshtml and render it without HTML entity encoding. The affected fields include message.Content, message.ForwardedMessage.Content, message.ReferencedMessage.Content, embed.Title, embed.Description, field.Name, and field.Value. A Discord webhook or bot can store a script payload in these fields, and the payload executes when a user exports the channel with markdown formatting disabled and opens the resulting HTML, allowing the script to read the export or alter its displayed content. This issue is fixed in version 2.47.2.

Affected products

DiscordChatExporter
  • ==< 2.47.2

Matching in nixpkgs

Package maintainers

Untriaged
Permalink CVE-2026-54681
4.1 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created suggestion
DiscordChatExporter: HTML attribute injection via unescaped emoji name in HTML export

DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, the VisitEmojiAsync method in DiscordChatExporter.Core/Exporting/HtmlMarkdownVisitor.cs interpolates emoji.Name into the alt attribute and emoji.Code into the title attribute without HTML entity encoding. This affects HTML exports regardless of the markdown setting. Discord's current custom emoji name validation normally excludes attribute-breaking characters, but tampered offline input, a relaxed upstream validation rule, or another future metadata source can inject an HTML attribute and execute script when a user opens the export. This issue is fixed in version 2.47.2.

Affected products

DiscordChatExporter
  • ==< 2.47.2

Matching in nixpkgs

Package maintainers