Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: ghostfolio

Found 5 matching suggestions

Dismissed
updated 1 week, 1 day ago by @mweinelt Activity log
  • Created automatic suggestion
  • @mweinelt accepted
  • @mweinelt dismissed
Ghostfolio: Full-Read SSRF in Manual Asset Import

Ghostfolio is an open source wealth management software. Prior to version 2.245.0, an attacker can exploit the manual asset import feature to perform a full-read SSRF, allowing them to exfiltrate sensitive cloud metadata (IMDS) or probe internal network services. This issue has been patched in version 2.245.0.

Affected products

ghostfolio
  • ==< 2.245.0

Matching in nixpkgs

Package maintainers

NixOS Unstable: https://github.com/NixOS/nixpkgs/pull/496350
NixOS 25.11: https://github.com/NixOS/nixpkgs/pull/497610
Published
updated 1 week, 1 day ago by @mweinelt Activity log
  • Created automatic suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub
Ghostfolio: Time-Based Blind SQL Injection in Manual Asset Import

Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an attacker can execute arbitrary SQL commands via the getHistorical() method, potentially allowing them to read, modify, or delete sensitive financial data for all users in the database. This issue has been patched in version 2.244.0.

Affected products

ghostfolio
  • ==< 2.244.0

Matching in nixpkgs

Package maintainers

NixOS Unstable fixed in https://github.com/NixOS/nixpkgs/pull/496350
Untriaged
created 3 weeks, 1 day ago
Ghost has a SQL Injection in its Content API

Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1.

Affected products

Ghost
  • ==>= 3.24.0, < 6.19.1

Matching in nixpkgs

Package maintainers

Untriaged
created 1 month, 2 weeks ago
Ghost vulnerable to XSS via malicious Portal preview links

Ghost is an open source content management system. In Ghost versions 5.43.0 through 5.12.04 and 6.0.0 through 6.14.0, an attacker was able to craft a malicious link that, when accessed by an authenticated staff user or member, would execute JavaScript with the victim's permissions, potentially leading to account takeover. Ghost Portal versions 2.29.1 through 2.51.4 and 2.52.0 through 2.57.0 were vulnerable to this issue. Ghost automatically loads the latest patch of the members Portal component via CDN. For Ghost 5.x users, upgrading to v5.121.0 or later fixes the vulnerability. v5.121.0 loads Portal v2.51.5, which contains the patch. For Ghost 6.x users, upgrading to v6.15.0 or later fixes the vulnerability. v6.15.0 loads Portal v2.57.1, which contains the patch. For Ghost installations using a customized or self-hosted version of Portal, it will be necessary to manually rebuild from or update to the latest patch version.

Affected products

Ghost
  • ==@tryghost/portal >= 2.29.1, < 2.51.5
  • ==ghost >= 5.43.0, < 5.121.0
  • ==ghost >= 6.0.0, < 6.15.0
  • ==@tryghost/portal >= 2.52.0, < 2.57.1

Matching in nixpkgs

pkgs.ghostty

Fast, native, feature-rich terminal emulator pushing modern features

pkgs.ghostunnel

TLS proxy with mutual authentication support for securing non-TLS backend applications

Package maintainers

Untriaged
created 5 months, 3 weeks ago
WordPress Ghost plugin <= 1.4.0 - Sensitive Data Exposure via Log File vulnerability

Insertion of Sensitive Information into Log File vulnerability in Ghost Foundation Ghost.This issue affects Ghost: from n/a through 1.4.0.

Affected products

ghost
  • =<1.4.0

Matching in nixpkgs

pkgs.ghost

Android post-exploitation framework

  • nixos-unstable -

pkgs.ghostie

Github notifications in your terminal

  • nixos-unstable -

pkgs.ghostty

Fast, native, feature-rich terminal emulator pushing modern features

  • nixos-unstable -

pkgs.ghost-cli

CLI Tool for installing & updating Ghost

  • nixos-unstable -

pkgs.ghostfolio

Open Source Wealth Management Software

pkgs.ghostunnel

TLS proxy with mutual authentication support for securing non-TLS backend applications

  • nixos-unstable -

pkgs.ghosttohugo

Convert Ghost export to Hugo posts

  • nixos-unstable -

pkgs.ghostty-bin

Fast, native, feature-rich terminal emulator pushing modern features

  • nixos-unstable -

Package maintainers