Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: gnomeExtensions.penguin-ai-chatbot

Found 7 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2026-97326
5.5 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Exploit Maturity (E): POC (P)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
created 4 days, 7 hours ago Activity log
  • Created suggestion
songxinjianqwe Chat chat-server ChatServer.java server-side request forgery

A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d. Affected by this issue is some unknown functionality of the file chat-server/src/main/java/cn/sinjinsong/chat/server/ChatServer.java of the component chat-server. This manipulation causes server-side request forgery. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

Chat
  • ==ac63d25297079eed5e4ba7e88d3b7a032637150d

Matching in nixpkgs

pkgs.chatd

Chat with your documents using local AI

  • nixos-unstable -
    • nixos-unstable-small 1.1.2
  • nixos-26.05 -
    • nixos-26.05-small 1.1.2

pkgs.kchat

Instant messaging service part of Infomaniak KSuite

  • nixos-unstable -
    • nixos-unstable-small 3.5.1
  • nixos-26.05 -
    • nixos-26.05-small 3.3.3

pkgs.nchat

Terminal-based chat client with support for Telegram and WhatsApp

  • nixos-unstable -
  • nixos-26.05 -

pkgs.aichat

Use GPT-4(V), Gemini, LocalAI, Ollama and other LLMs in the terminal

  • nixos-unstable -
  • nixos-26.05 -

pkgs.chatty

XMPP and SMS messaging via libpurple and ModemManager

  • nixos-unstable -
    • nixos-unstable-small 0.8.9
  • nixos-26.05 -
    • nixos-26.05-small 0.8.9

pkgs.ttchat

Connect to a Twitch channel's chat from your terminal

  • nixos-unstable -
  • nixos-26.05 -

pkgs.wechat

Messaging and calling app

  • nixos-unstable -
  • nixos-26.05 -

pkgs.weechat

Fast, light and extensible chat client

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ssh-chat

Chat over SSH

  • nixos-unstable -
  • nixos-26.05 -

pkgs.chatblade

CLI Swiss Army Knife for ChatGPT

  • nixos-unstable -
    • nixos-unstable-small 0.7.0
  • nixos-26.05 -
    • nixos-26.05-small 0.7.0

pkgs.librechat

Open-source app for all your AI conversations, fully customizable and compatible with any AI provider

  • nixos-unstable -
    • nixos-unstable-small 0.8.7
  • nixos-26.05 -
    • nixos-26.05-small 0.8.6

pkgs.aider-chat

AI pair programming in your terminal

  • nixos-unstable -
  • nixos-26.05 -

pkgs.fluffychat

Chat with your friends (matrix client)

  • nixos-unstable -
    • nixos-unstable-small 2.9.4
  • nixos-26.05 -
    • nixos-26.05-small 2.6.0

pkgs.chatgpt-cli

Interactive CLI for ChatGPT

  • nixos-unstable -
    • nixos-unstable-small 1.3.5
  • nixos-26.05 -
    • nixos-26.05-small 1.3.5

pkgs.chatterino2

Chat client for Twitch chat

  • nixos-unstable -
    • nixos-unstable-small 2.5.5
  • nixos-26.05 -
    • nixos-26.05-small 2.5.5

pkgs.chatterino7

Chat client for Twitch chat

  • nixos-unstable -
    • nixos-unstable-small 7.5.5
  • nixos-26.05 -
    • nixos-26.05-small 7.5.5

pkgs.commet-chat

Client for Matrix focused on providing a feature rich experience while maintaining a simple interface

pkgs.libdeltachat

Delta Chat Rust Core library

  • nixos-unstable -
  • nixos-26.05 -

pkgs.libgnunetchat

Library for secure, decentralized chat using GNUnet network services

  • nixos-unstable -
    • nixos-unstable-small 0.6.1
  • nixos-26.05 -
    • nixos-26.05-small 0.6.1

pkgs.arcanechat-tui

Lightweight Delta Chat client

  • nixos-unstable -
  • nixos-26.05 -

pkgs.fluffychat-web

Chat with your friends (matrix client)

  • nixos-unstable -
    • nixos-unstable-small 2.9.4
  • nixos-26.05 -
    • nixos-26.05-small 2.6.0

pkgs.pkgsRocm.chatd

Chat with your documents using local AI

  • nixos-unstable -
    • nixos-unstable-small 1.1.2
  • nixos-26.05 -
    • nixos-26.05-small 1.1.2

pkgs.aider-chat-full

AI pair programming in your terminal

  • nixos-unstable -
  • nixos-26.05 -

pkgs.chatzone-desktop

Ozon corporate messenger

  • nixos-unstable -
    • nixos-unstable-small 5.7.0
  • nixos-26.05 -
    • nixos-26.05-small 5.7.0

pkgs.chatgpt-shell-cli

Simple shell script to use OpenAI's ChatGPT and DALL-E from the terminal. No Python or JS required

  • nixos-unstable -
    • nixos-unstable-small
  • nixos-26.05 -
    • nixos-26.05-small

pkgs.deltachat-desktop

Email-based instant messaging for Desktop

  • nixos-unstable -
  • nixos-26.05 -

pkgs.weechat-unwrapped

Fast, light and extensible chat client

  • nixos-unstable -
  • nixos-26.05 -

pkgs.mautrix-googlechat

Matrix-Google Chat puppeting bridge

  • nixos-unstable -
    • nixos-unstable-small 0.5.2
  • nixos-26.05 -
    • nixos-26.05-small 0.5.2

pkgs.kdePackages.neochat

A client for matrix, the decentralized communication protocol

  • nixos-unstable -
  • nixos-26.05 -

pkgs.weechatScripts.edit

This simple weechat plugin allows you to compose messages in your $EDITOR

  • nixos-unstable -
    • nixos-unstable-small 1.0.2
  • nixos-26.05 -
    • nixos-26.05-small 1.0.2

pkgs.deltachat-rpc-server

Delta Chat RPC server exposing JSON-RPC core API over standard I/O

  • nixos-unstable -
  • nixos-26.05 -

pkgs.reticulum-group-chat

Pure-Go LXMF group-chat hub for the Reticulum network — a single static binary that relays many-to-many encrypted text chat over LoRa, TCP/IP, and mixed meshes. No Python, no third-party RNS library

  • nixos-unstable -

pkgs.weechatScripts.autosort

autosort automatically keeps your buffers sorted and grouped by server

  • nixos-unstable -
    • nixos-unstable-small 3.10
  • nixos-26.05 -
    • nixos-26.05-small 3.10

pkgs.python313Packages.fschat

Open platform for training, serving, and evaluating large language models. Release repo for Vicuna and Chatbot Arena

  • nixos-unstable -
  • nixos-26.05 -

pkgs.python314Packages.fschat

Open platform for training, serving, and evaluating large language models. Release repo for Vicuna and Chatbot Arena

  • nixos-unstable -
  • nixos-26.05 -

pkgs.python313Packages.chatlas

Friendly guide to building LLM chat apps in Python with less effort and more clarity

  • nixos-unstable -
  • nixos-26.05 -

pkgs.python314Packages.chatlas

Friendly guide to building LLM chat apps in Python with less effort and more clarity

  • nixos-unstable -
  • nixos-26.05 -

pkgs.weechatScripts.weechat-go

WeeChat script to quickly jump to different buffers

  • nixos-unstable -
    • nixos-unstable-small 2.7
  • nixos-26.05 -
    • nixos-26.05-small 2.7

pkgs.weechatScripts.weechat-autosort

Autosort is a weechat script to automatically or manually keep your buffers sorted

  • nixos-unstable -
    • nixos-unstable-small 3.9
  • nixos-26.05 -
    • nixos-26.05-small 3.9

pkgs.python313Packages.chat-downloader

Simple tool used to retrieve chat messages from livestreams, videos, clips and past broadcasts

  • nixos-unstable -
    • nixos-unstable-small 0.2.8
  • nixos-26.05 -
    • nixos-26.05-small 0.2.8

pkgs.python314Packages.chat-downloader

Simple tool used to retrieve chat messages from livestreams, videos, clips and past broadcasts

  • nixos-unstable -
    • nixos-unstable-small 0.2.8
  • nixos-26.05 -
    • nixos-26.05-small 0.2.8

pkgs.gnomeExtensions.penguin-ai-chatbot

A GNOME Shell extension that provides a chatbot interface using various LLM providers, including Anthropic, OpenAI, Gemini, and OpenRouter. Features include multiple provider support, customizable models, chat history, customizable appearance, a keyboard shortcut, web search, location (by using the extension, you consent to sharing your location with OpenRouter for AI Tools) and copy-to-clipboard functionality.

  • nixos-unstable -
    • nixos-unstable-small 28
  • nixos-26.05 -
    • nixos-26.05-small 25

Package maintainers

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-57363
7.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 2 months, 2 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
WordPress ChatBot plugin <= 8.3.7 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot chatbot allows Stored XSS.This issue affects ChatBot: from n/a through <= 8.3.7.

Affected products

chatbot
  • =<8.3.7

Matching in nixpkgs

pkgs.gnomeExtensions.penguin-ai-chatbot

A GNOME Shell extension that provides a chatbot interface using various LLM providers, including Anthropic, OpenAI, Gemini, and OpenRouter. Features include multiple provider support, customizable models, chat history, customizable appearance, a keyboard shortcut, and copy-to-clipboard functionality.

  • nixos-unstable 25
    • nixpkgs-unstable 25
    • nixos-unstable-small 25
  • nixos-26.05 25
    • nixos-26.05-small 25
    • nixpkgs-26.05-darwin 25

Package maintainers

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-57362
7.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 2 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
WordPress ChatBot plugin <= 8.3.2 - Reflected Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in ChatBot <= 8.3.2 versions.

Affected products

ChatBot
  • =<8.3.2

Matching in nixpkgs

pkgs.gnomeExtensions.penguin-ai-chatbot

A GNOME Shell extension that provides a chatbot interface using various LLM providers, including Anthropic, OpenAI, Gemini, and OpenRouter. Features include multiple provider support, customizable models, chat history, customizable appearance, a keyboard shortcut, and copy-to-clipboard functionality.

  • nixos-unstable 25
    • nixpkgs-unstable 25
    • nixos-unstable-small 25
  • nixos-26.05 25
    • nixos-26.05-small 25
    • nixpkgs-26.05-darwin 25
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-40788
7.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): High (H)
updated 3 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
WordPress ChatBot plugin <= 7.9.7 - Broken Access Control vulnerability

Subscriber Broken Access Control in ChatBot <= 7.9.7 versions.

Affected products

chatbot
  • =<7.9.7

Matching in nixpkgs

pkgs.gnomeExtensions.penguin-ai-chatbot

A GNOME Shell extension that provides a chatbot interface using various LLM providers, including Anthropic, OpenAI, Gemini, and OpenRouter. Features include multiple provider support, customizable models, chat history, customizable appearance, a keyboard shortcut, and copy-to-clipboard functionality.

  • nixos-unstable 25
    • nixos-unstable-small 25
  • nixos-26.05 -
    • nixos-26.05-small 25
    • nixpkgs-26.05-darwin 25
Dismissed
(not in Nixpkgs)
updated 6 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
WordPress ChatBot plugin <= 7.7.9 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud ChatBot chatbot allows Blind SQL Injection.This issue affects ChatBot: from n/a through <= 7.7.9.

Affected products

chatbot
  • =<<= 7.7.9

Matching in nixpkgs

pkgs.gnomeExtensions.penguin-ai-chatbot

A GNOME Shell extension that provides a chatbot interface using various LLM providers, including Anthropic, OpenAI, Gemini, and OpenRouter. Features include multiple provider support, customizable models, chat history, customizable appearance, a keyboard shortcut, and copy-to-clipboard functionality.

  • nixos-unstable -
    • nixpkgs-unstable 25
    • nixos-unstable-small 25

Package maintainers

Dismissed
Permalink CVE-2025-62952
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 9 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed
WordPress ChatBot plugin <= 7.3.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ChatBot: from n/a through <= 7.3.0.

Affected products

chatbot
  • =<<= 7.3.0

Matching in nixpkgs

pkgs.gnomeExtensions.penguin-ai-chatbot

A GNOME Shell extension that provides a chatbot interface using various LLM providers, including Anthropic, OpenAI, Gemini, and OpenRouter. Features include multiple provider support, customizable models, chat history, customizable appearance, a keyboard shortcut, and copy-to-clipboard functionality.

  • nixos-unstable 22
    • nixpkgs-unstable 22
    • nixos-unstable-small 22

Package maintainers

Dismissed
Permalink CVE-2025-64277
5.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 9 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed
WordPress ChatBot plugin <= 7.3.9 - Broken Access Control vulnerability

Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ChatBot: from n/a through <= 7.3.9.

Affected products

chatbot
  • =<<= 7.3.9

Matching in nixpkgs

pkgs.gnomeExtensions.penguin-ai-chatbot

A GNOME Shell extension that provides a chatbot interface using various LLM providers, including Anthropic, OpenAI, Gemini, and OpenRouter. Features include multiple provider support, customizable models, chat history, customizable appearance, a keyboard shortcut, and copy-to-clipboard functionality.

  • nixos-unstable 22
    • nixpkgs-unstable 22
    • nixos-unstable-small 22

Package maintainers