Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: kodiPackages.steam-controller

Found 12 matching suggestions

View:
Compact
Detailed
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-95592
5.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
WordPress Team plugin <= 6.0.0 - Insecure Direct Object References (IDOR) vulnerability

Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions.

Affected products

tlp-team
  • =<6.0.0

Matching in nixpkgs

pkgs.steam

Digital distribution platform

  • nixos-unstable -
  • nixos-26.05 -

pkgs.git-team

Command line interface for managing and enhancing git commit messages with co-authors

  • nixos-unstable -
    • nixos-unstable-small 2.0.0
  • nixos-26.05 -
    • nixos-26.05-small 1.8.1

pkgs.steamcmd

Steam command-line tools

  • nixos-unstable -
  • nixos-26.05 -

pkgs.teamocil

Simple tool used to automatically create windows and panes in tmux with YAML files

  • nixos-unstable -
    • nixos-unstable-small 1.4.2
  • nixos-26.05 -
    • nixos-26.05-small 1.4.2

pkgs.teamtype

Real-time co-editing of local text files

  • nixos-unstable -
    • nixos-unstable-small 0.9.2
  • nixos-26.05 -
    • nixos-26.05-small 0.9.2

pkgs.ethersync

Real-time co-editing of local text files

  • nixos-unstable -
    • nixos-unstable-small 0.9.2
  • nixos-26.05 -
    • nixos-26.05-small 0.9.2

pkgs.steam-acf

Tool to convert Steam .acf files to JSON

  • nixos-unstable -
    • nixos-unstable-small 0.1.0
  • nixos-26.05 -
    • nixos-26.05-small 0.1.0

pkgs.steam-run

Run commands in the same FHS environment that is used for Steam

  • nixos-unstable -
  • nixos-26.05 -

pkgs.steam-tui

Rust TUI client for steamcmd

  • nixos-unstable -
    • nixos-unstable-small 0.3.0
  • nixos-26.05 -
    • nixos-26.05-small 0.3.0

pkgs.steamback

Decky plugin to add versioned save-game snapshots to Steam-cloud enabled games

  • nixos-unstable -
    • nixos-unstable-small 0.3.6
  • nixos-26.05 -
    • nixos-26.05-small 0.3.6

pkgs.steampipe

Dynamically query your cloud, code, logs & more with SQL

  • nixos-unstable -
    • nixos-unstable-small 2.4.7
  • nixos-26.05 -
    • nixos-26.05-small 2.4.5

pkgs.steamworks

Configuration information distributed over LDAP in near realtime

  • nixos-unstable -
  • nixos-26.05 -

pkgs.teamviewer

Desktop sharing application, providing remote support and online meetings

  • nixos-unstable -
  • nixos-26.05 -

pkgs.adwsteamgtk

Simple Gtk wrapper for Adwaita-for-Steam

  • nixos-unstable -
    • nixos-unstable-small 0.8.0
  • nixos-26.05 -
    • nixos-26.05-small 0.8.0

pkgs.bitlbee-steam

Steam protocol plugin for BitlBee

  • nixos-unstable -
    • nixos-unstable-small 1.4.2
  • nixos-26.05 -
    • nixos-26.05-small 1.4.2

pkgs.ArchiSteamFarm

Application with primary purpose of idling Steam cards from multiple accounts simultaneously

  • nixos-unstable -
  • nixos-26.05 -

pkgs.archisteamfarm

Application with primary purpose of idling Steam cards from multiple accounts simultaneously

  • nixos-unstable -
  • nixos-26.05 -

pkgs.steam-run-free

Run commands in the same FHS environment that is used for Steam

  • nixos-unstable -
  • nixos-26.05 -

pkgs.steamguard-cli

Linux utility for generating 2FA codes for Steam and managing Steam trade confirmations

  • nixos-unstable -
  • nixos-26.05 -

pkgs.teams-for-linux

Unofficial Microsoft Teams client for Linux

  • nixos-unstable -
  • nixos-26.05 -

pkgs.teamspeak_server

TeamSpeak voice communication server

  • nixos-unstable -
  • nixos-26.05 -

pkgs.steam-art-manager

A tool to manage and change Steam library artwork

  • nixos-unstable -
  • nixos-26.05 -

pkgs.steamvr-linux-fixes

Vulkan layer that patches SteamVR vrcompositor for wired HMDs

  • nixos-unstable -
    • nixos-unstable-small 0.1.4

pkgs.vimPlugins.teamtype

Real-time co-editing of local text files

  • nixos-unstable -
    • nixos-unstable-small 0.9.2
  • nixos-26.05 -
    • nixos-26.05-small 0.9.2

pkgs.steam-lancache-prefill

Automatically fills a Lancache with games from Steam

  • nixos-unstable -
    • nixos-unstable-small 3.6.1
  • nixos-26.05 -
    • nixos-26.05-small 3.4.2

pkgs.python313Packages.steamodd

High level Steam API implementation with low level reusable core

  • nixos-unstable -
    • nixos-unstable-small 5.0
  • nixos-26.05 -
    • nixos-26.05-small 5.0

pkgs.python314Packages.steamodd

High level Steam API implementation with low level reusable core

  • nixos-unstable -
    • nixos-unstable-small 5.0
  • nixos-26.05 -
    • nixos-26.05-small 5.0

pkgs.gnomeExtensions.add-to-steam

Add executables to steam without having to open, or restart steam; Just like SteamOS.

  • nixos-unstable -
    • nixos-unstable-small 4
  • nixos-26.05 -
    • nixos-26.05-small 3

Package maintainers

Dismissed
(not in Nixpkgs)
Permalink CVE-2025-36421
5.9 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 days, 1 hour ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Multiple vulnerabilities in IBM Controller

IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.

References

Affected products

Controller
  • =<11.1.3 FP1
  • =<11.0.1 FP7

Matching in nixpkgs

pkgs.unifi

Controller for Ubiquiti UniFi access points

  • nixos-unstable -
  • nixos-26.05 -

pkgs.sc-controller

User-mode driver and GUI for Steam Controller and other controllers

  • nixos-unstable -
    • nixos-unstable-small 0.7.2
  • nixos-26.05 -
    • nixos-26.05-small 0.6.2

pkgs.pid-fan-controller

Service to provide closed-loop PID fan control

  • nixos-unstable -
    • nixos-unstable-small 0.1.5
  • nixos-26.05 -
    • nixos-26.05-small 0.1.3

pkgs.gnomeExtensions.media-controller

Show the currently playing media in the top panel with playback controls and an iOS-inspired now-playing card. Works with any MPRIS-compatible player, including Spotify, Firefox, Chrome, VLC, mpv, Rhythmbox, and more.

  • nixos-unstable -
    • nixos-unstable-small 9

pkgs.gnomeExtensions.spotify-controller

A feature-rich Spotify controller for GNOME Shell with a beautiful popup UI.

  • nixos-unstable -
    • nixos-unstable-small 4
  • nixos-26.05 -
    • nixos-26.05-small 4

pkgs.gnomeExtensions.awesome-media-controller

Aurora Glass media controls in the GNOME top bar. Full-card popup with album art, progress, volume, shuffle, repeat, and multi-player switching.

  • nixos-unstable -
    • nixos-unstable-small 1

pkgs.gnomeExtensions.advanced-media-controller

Take control of all your music and media from one stylish spot in your GNOME panel — no more switching windows just to skip a track.

  • nixos-unstable -
    • nixos-unstable-small 31
  • nixos-26.05 -
    • nixos-26.05-small 23

pkgs.gnomeExtensions.ddc-brightness-controller

Control display brightness via DDC/CI using ddcutil. Bind keyboard shortcuts or use the panel menu to adjust monitor brightness.

  • nixos-unstable -
    • nixos-unstable-small 1

pkgs.gnomeExtensions.xbox-controller-indicator

Shows connected Xbox/gamepad controllers as colored icons in the panel. Configure colors per MAC address in the preferences.

  • nixos-unstable -
    • nixos-unstable-small 3

pkgs.gnomeExtensions.streamcontroller-integration

Allow automatic page switching in StreamController by adding a dbus interface to fetch info about the current window.

  • nixos-unstable -
    • nixos-unstable-small 7
  • nixos-26.05 -
    • nixos-26.05-small 6

Package maintainers

Dismissed
(not in Nixpkgs)
Permalink CVE-2025-1350
5.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 days, 2 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Multiple vulnerabilities in IBM Controller

IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

References

Affected products

Controller
  • =<11.1.3 FP1
  • =<11.0.1 FP7

Matching in nixpkgs

pkgs.unifi

Controller for Ubiquiti UniFi access points

  • nixos-unstable -
  • nixos-26.05 -

pkgs.sc-controller

User-mode driver and GUI for Steam Controller and other controllers

  • nixos-unstable -
    • nixos-unstable-small 0.7.2
  • nixos-26.05 -
    • nixos-26.05-small 0.6.2

pkgs.pid-fan-controller

Service to provide closed-loop PID fan control

  • nixos-unstable -
    • nixos-unstable-small 0.1.5
  • nixos-26.05 -
    • nixos-26.05-small 0.1.3

pkgs.gnomeExtensions.media-controller

Show the currently playing media in the top panel with playback controls and an iOS-inspired now-playing card. Works with any MPRIS-compatible player, including Spotify, Firefox, Chrome, VLC, mpv, Rhythmbox, and more.

  • nixos-unstable -
    • nixos-unstable-small 9

pkgs.gnomeExtensions.spotify-controller

A feature-rich Spotify controller for GNOME Shell with a beautiful popup UI.

  • nixos-unstable -
    • nixos-unstable-small 4
  • nixos-26.05 -
    • nixos-26.05-small 4

pkgs.gnomeExtensions.awesome-media-controller

Aurora Glass media controls in the GNOME top bar. Full-card popup with album art, progress, volume, shuffle, repeat, and multi-player switching.

  • nixos-unstable -
    • nixos-unstable-small 1

pkgs.gnomeExtensions.advanced-media-controller

Take control of all your music and media from one stylish spot in your GNOME panel — no more switching windows just to skip a track.

  • nixos-unstable -
    • nixos-unstable-small 31
  • nixos-26.05 -
    • nixos-26.05-small 23

pkgs.gnomeExtensions.ddc-brightness-controller

Control display brightness via DDC/CI using ddcutil. Bind keyboard shortcuts or use the panel menu to adjust monitor brightness.

  • nixos-unstable -
    • nixos-unstable-small 1

pkgs.gnomeExtensions.xbox-controller-indicator

Shows connected Xbox/gamepad controllers as colored icons in the panel. Configure colors per MAC address in the preferences.

  • nixos-unstable -
    • nixos-unstable-small 3

pkgs.gnomeExtensions.streamcontroller-integration

Allow automatic page switching in StreamController by adding a dbus interface to fetch info about the current window.

  • nixos-unstable -
    • nixos-unstable-small 7
  • nixos-26.05 -
    • nixos-26.05-small 6

Package maintainers

Untriaged
Permalink CVE-2026-53908
6.9 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 months, 3 weeks ago Activity log
  • Created suggestion
User Enumeration in MCO

MCO is vulnerable to User Enumeration through authentication-related functionalities. The application returns distinguishable responses for valid and invalid users during username reminder and password reset operations. An attacker can leverage these differences to enumerate valid usernames and email addresses. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions.

Affected products

MCO
  • ==25.3.3.1

Matching in nixpkgs

pkgs.ghdl

VHDL 2008/93/87 simulator

  • nixos-unstable -
    • nixos-unstable-small 6.0.0
  • nixos-26.05 -
    • nixos-26.05-small 6.0.0

pkgs.mcomix

Comic book reader and image viewer

  • nixos-unstable -
    • nixos-unstable-small 3.1.1
  • nixos-26.05 -
    • nixos-26.05-small 3.1.1

pkgs.termcolor

Header-only C++ library for printing colored messages

  • nixos-unstable -
    • nixos-unstable-small 2.1.0
  • nixos-26.05 -
    • nixos-26.05-small 2.1.0

pkgs.ghdl-mcode

VHDL 2008/93/87 simulator

  • nixos-unstable -
    • nixos-unstable-small 6.0.0
  • nixos-26.05 -
    • nixos-26.05-small 6.0.0

pkgs.xtermcontrol

Enables dynamic control of xterm properties

  • nixos-unstable -
    • nixos-unstable-small 3.10
  • nixos-26.05 -
    • nixos-26.05-small 3.10

pkgs.mcontrolcenter

Tool to change the settings of MSI laptops running Linux

  • nixos-unstable -
    • nixos-unstable-small 0.5.1
  • nixos-26.05 -
    • nixos-26.05-small 0.5.1

pkgs.python313Packages.numcodecs

Buffer compression and transformation codecs for use in data storage and communication applications

  • nixos-unstable -
  • nixos-26.05 -

pkgs.python314Packages.numcodecs

Buffer compression and transformation codecs for use in data storage and communication applications

  • nixos-unstable -
  • nixos-26.05 -

pkgs.gnomeExtensions.streamcontroller-integration

Allow automatic page switching in StreamController by adding a dbus interface to fetch info about the current window.

  • nixos-unstable -
    • nixos-unstable-small 7
  • nixos-26.05 -
    • nixos-26.05-small 6
Untriaged
Permalink CVE-2026-53904
6.3 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 months, 3 weeks ago Activity log
  • Created suggestion
Account Denial of Service in MCO

MCO is vulnerable to Account Denial of Service due to improper implementation of password reset functionality. Each password reset request invalidates previously set password as well as previously issued temporary passwords, furthermore, password resets are not limited in any way. An attacker who provides victim's email and answer to their security question, can successfully initiate the reset process and continuously invalidate credentials, effectively locking the victim out of their account. Answering security questions has a limited number of tries which lowers the risk of this vulnerability. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions.

Affected products

MCO
  • ==25.3.3.1

Matching in nixpkgs

pkgs.ghdl

VHDL 2008/93/87 simulator

  • nixos-unstable -
    • nixos-unstable-small 6.0.0
  • nixos-26.05 -
    • nixos-26.05-small 6.0.0

pkgs.mcomix

Comic book reader and image viewer

  • nixos-unstable -
    • nixos-unstable-small 3.1.1
  • nixos-26.05 -
    • nixos-26.05-small 3.1.1

pkgs.termcolor

Header-only C++ library for printing colored messages

  • nixos-unstable -
    • nixos-unstable-small 2.1.0
  • nixos-26.05 -
    • nixos-26.05-small 2.1.0

pkgs.ghdl-mcode

VHDL 2008/93/87 simulator

  • nixos-unstable -
    • nixos-unstable-small 6.0.0
  • nixos-26.05 -
    • nixos-26.05-small 6.0.0

pkgs.xtermcontrol

Enables dynamic control of xterm properties

  • nixos-unstable -
    • nixos-unstable-small 3.10
  • nixos-26.05 -
    • nixos-26.05-small 3.10

pkgs.mcontrolcenter

Tool to change the settings of MSI laptops running Linux

  • nixos-unstable -
    • nixos-unstable-small 0.5.1
  • nixos-26.05 -
    • nixos-26.05-small 0.5.1

pkgs.python313Packages.numcodecs

Buffer compression and transformation codecs for use in data storage and communication applications

  • nixos-unstable -
  • nixos-26.05 -

pkgs.python314Packages.numcodecs

Buffer compression and transformation codecs for use in data storage and communication applications

  • nixos-unstable -
  • nixos-26.05 -

pkgs.gnomeExtensions.streamcontroller-integration

Allow automatic page switching in StreamController by adding a dbus interface to fetch info about the current window.

  • nixos-unstable -
    • nixos-unstable-small 7
  • nixos-26.05 -
    • nixos-26.05-small 6
Untriaged
Permalink CVE-2026-53907
4.8 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): Passive (P)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): Low (L)
  • Subsequent System Impact Integrity (SI): Low (L)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): Passive (P)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Low (L)
  • Modified Subsequent System Impact Integrity (MSI): Low (L)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 months, 3 weeks ago Activity log
  • Created suggestion
Stored Cross‑Site Scripting in MCO

MCO is vulnerable to Stored Cross‑Site Scripting (XSS) via the application logo upload functionality. An attacker with the ability to change the application logo can upload a crafted SVG file containing malicious JavaScript code that is executed when the logo is rendered or opened. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions.

Affected products

MCO
  • ==25.3.3.1

Matching in nixpkgs

pkgs.ghdl

VHDL 2008/93/87 simulator

  • nixos-unstable -
    • nixos-unstable-small 6.0.0
  • nixos-26.05 -
    • nixos-26.05-small 6.0.0

pkgs.mcomix

Comic book reader and image viewer

  • nixos-unstable -
    • nixos-unstable-small 3.1.1
  • nixos-26.05 -
    • nixos-26.05-small 3.1.1

pkgs.termcolor

Header-only C++ library for printing colored messages

  • nixos-unstable -
    • nixos-unstable-small 2.1.0
  • nixos-26.05 -
    • nixos-26.05-small 2.1.0

pkgs.ghdl-mcode

VHDL 2008/93/87 simulator

  • nixos-unstable -
    • nixos-unstable-small 6.0.0
  • nixos-26.05 -
    • nixos-26.05-small 6.0.0

pkgs.xtermcontrol

Enables dynamic control of xterm properties

  • nixos-unstable -
    • nixos-unstable-small 3.10
  • nixos-26.05 -
    • nixos-26.05-small 3.10

pkgs.mcontrolcenter

Tool to change the settings of MSI laptops running Linux

  • nixos-unstable -
    • nixos-unstable-small 0.5.1
  • nixos-26.05 -
    • nixos-26.05-small 0.5.1

pkgs.python313Packages.numcodecs

Buffer compression and transformation codecs for use in data storage and communication applications

  • nixos-unstable -
  • nixos-26.05 -

pkgs.python314Packages.numcodecs

Buffer compression and transformation codecs for use in data storage and communication applications

  • nixos-unstable -
  • nixos-26.05 -

pkgs.gnomeExtensions.streamcontroller-integration

Allow automatic page switching in StreamController by adding a dbus interface to fetch info about the current window.

  • nixos-unstable -
    • nixos-unstable-small 7
  • nixos-26.05 -
    • nixos-26.05-small 6
Untriaged
Permalink CVE-2026-53905
5.3 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 months, 3 weeks ago Activity log
  • Created suggestion
Unauthorized Access to Administrator ACL View in MCO

MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree-structure endpoint. An authenticated, low-privileged user can retrieve administrator access control structures without proper authorization checks. This may expose sensitive permission mappings and internal configuration details. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions.

Affected products

MCO
  • ==25.3.3.1

Matching in nixpkgs

pkgs.ghdl

VHDL 2008/93/87 simulator

  • nixos-unstable -
    • nixos-unstable-small 6.0.0
  • nixos-26.05 -
    • nixos-26.05-small 6.0.0

pkgs.mcomix

Comic book reader and image viewer

  • nixos-unstable -
    • nixos-unstable-small 3.1.1
  • nixos-26.05 -
    • nixos-26.05-small 3.1.1

pkgs.termcolor

Header-only C++ library for printing colored messages

  • nixos-unstable -
    • nixos-unstable-small 2.1.0
  • nixos-26.05 -
    • nixos-26.05-small 2.1.0

pkgs.ghdl-mcode

VHDL 2008/93/87 simulator

  • nixos-unstable -
    • nixos-unstable-small 6.0.0
  • nixos-26.05 -
    • nixos-26.05-small 6.0.0

pkgs.xtermcontrol

Enables dynamic control of xterm properties

  • nixos-unstable -
    • nixos-unstable-small 3.10
  • nixos-26.05 -
    • nixos-26.05-small 3.10

pkgs.mcontrolcenter

Tool to change the settings of MSI laptops running Linux

  • nixos-unstable -
    • nixos-unstable-small 0.5.1
  • nixos-26.05 -
    • nixos-26.05-small 0.5.1

pkgs.python313Packages.numcodecs

Buffer compression and transformation codecs for use in data storage and communication applications

  • nixos-unstable -
  • nixos-26.05 -

pkgs.python314Packages.numcodecs

Buffer compression and transformation codecs for use in data storage and communication applications

  • nixos-unstable -
  • nixos-26.05 -

pkgs.gnomeExtensions.streamcontroller-integration

Allow automatic page switching in StreamController by adding a dbus interface to fetch info about the current window.

  • nixos-unstable -
    • nixos-unstable-small 7
  • nixos-26.05 -
    • nixos-26.05-small 6
Untriaged
Permalink CVE-2026-53902
7.1 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 months, 3 weeks ago Activity log
  • Created suggestion
Privilege Escalation in MCO

MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/profile-sections/group-membership endpoint. An authenticated user can modify their group membership without proper authorization checks, allowing privilege escalation. An attacker can add themselves to arbitrary groups by supplying a valid group ID, which can be obtained via other application functionalities (e.g. /customer/servlet/mco/webapi/group/picker/groups), provided he has necessary permissions, or potentially inferred through brute-force techniques. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions.

Affected products

MCO
  • ==25.3.3.1

Matching in nixpkgs

pkgs.ghdl

VHDL 2008/93/87 simulator

  • nixos-unstable -
    • nixos-unstable-small 6.0.0
  • nixos-26.05 -
    • nixos-26.05-small 6.0.0

pkgs.mcomix

Comic book reader and image viewer

  • nixos-unstable -
    • nixos-unstable-small 3.1.1
  • nixos-26.05 -
    • nixos-26.05-small 3.1.1

pkgs.termcolor

Header-only C++ library for printing colored messages

  • nixos-unstable -
    • nixos-unstable-small 2.1.0
  • nixos-26.05 -
    • nixos-26.05-small 2.1.0

pkgs.ghdl-mcode

VHDL 2008/93/87 simulator

  • nixos-unstable -
    • nixos-unstable-small 6.0.0
  • nixos-26.05 -
    • nixos-26.05-small 6.0.0

pkgs.xtermcontrol

Enables dynamic control of xterm properties

  • nixos-unstable -
    • nixos-unstable-small 3.10
  • nixos-26.05 -
    • nixos-26.05-small 3.10

pkgs.mcontrolcenter

Tool to change the settings of MSI laptops running Linux

  • nixos-unstable -
    • nixos-unstable-small 0.5.1
  • nixos-26.05 -
    • nixos-26.05-small 0.5.1

pkgs.python313Packages.numcodecs

Buffer compression and transformation codecs for use in data storage and communication applications

  • nixos-unstable -
  • nixos-26.05 -

pkgs.python314Packages.numcodecs

Buffer compression and transformation codecs for use in data storage and communication applications

  • nixos-unstable -
  • nixos-26.05 -

pkgs.gnomeExtensions.streamcontroller-integration

Allow automatic page switching in StreamController by adding a dbus interface to fetch info about the current window.

  • nixos-unstable -
    • nixos-unstable-small 7
  • nixos-26.05 -
    • nixos-26.05-small 6
Untriaged
Permalink CVE-2026-53909
5.3 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): Low (L)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Low (L)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 months, 3 weeks ago Activity log
  • Created suggestion
Arbitrary File Upload in MCO

MCO does not correctly validate types of uploaded files. File upload validation functionality relies only on client-side checks, which can be bypassed. An authorized, low-privileged attacker can upload files with arbitrary types to the server. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions.

Affected products

MCO
  • ==25.3.3.1

Matching in nixpkgs

pkgs.ghdl

VHDL 2008/93/87 simulator

  • nixos-unstable -
    • nixos-unstable-small 6.0.0
  • nixos-26.05 -
    • nixos-26.05-small 6.0.0

pkgs.mcomix

Comic book reader and image viewer

  • nixos-unstable -
    • nixos-unstable-small 3.1.1
  • nixos-26.05 -
    • nixos-26.05-small 3.1.1

pkgs.termcolor

Header-only C++ library for printing colored messages

  • nixos-unstable -
    • nixos-unstable-small 2.1.0
  • nixos-26.05 -
    • nixos-26.05-small 2.1.0

pkgs.ghdl-mcode

VHDL 2008/93/87 simulator

  • nixos-unstable -
    • nixos-unstable-small 6.0.0
  • nixos-26.05 -
    • nixos-26.05-small 6.0.0

pkgs.xtermcontrol

Enables dynamic control of xterm properties

  • nixos-unstable -
    • nixos-unstable-small 3.10
  • nixos-26.05 -
    • nixos-26.05-small 3.10

pkgs.mcontrolcenter

Tool to change the settings of MSI laptops running Linux

  • nixos-unstable -
    • nixos-unstable-small 0.5.1
  • nixos-26.05 -
    • nixos-26.05-small 0.5.1

pkgs.python313Packages.numcodecs

Buffer compression and transformation codecs for use in data storage and communication applications

  • nixos-unstable -
  • nixos-26.05 -

pkgs.python314Packages.numcodecs

Buffer compression and transformation codecs for use in data storage and communication applications

  • nixos-unstable -
  • nixos-26.05 -

pkgs.gnomeExtensions.streamcontroller-integration

Allow automatic page switching in StreamController by adding a dbus interface to fetch info about the current window.

  • nixos-unstable -
    • nixos-unstable-small 7
  • nixos-26.05 -
    • nixos-26.05-small 6
Untriaged
Permalink CVE-2026-53903
5.3 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 months, 3 weeks ago Activity log
  • Created suggestion
Insecure Direct Object Reference in MCO

MCO is vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability in the /customer/servlet/mco/webapi/trading-document/fetchPdfStatement endpoint. The application does not properly validate whether an authenticated user is authorized to access a requested document, allowing direct retrieval based on a user-supplied identifier. An attacker can access trading documents belonging to other users by providing a valid document ID. Although exploitation requires guessing the identifier, predictable ID patterns enable feasible enumeration, leading to unauthorized disclosure of sensitive information. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions.

Affected products

MCO
  • ==25.3.3.1

Matching in nixpkgs

pkgs.ghdl

VHDL 2008/93/87 simulator

  • nixos-unstable -
    • nixos-unstable-small 6.0.0
  • nixos-26.05 -
    • nixos-26.05-small 6.0.0

pkgs.mcomix

Comic book reader and image viewer

  • nixos-unstable -
    • nixos-unstable-small 3.1.1
  • nixos-26.05 -
    • nixos-26.05-small 3.1.1

pkgs.termcolor

Header-only C++ library for printing colored messages

  • nixos-unstable -
    • nixos-unstable-small 2.1.0
  • nixos-26.05 -
    • nixos-26.05-small 2.1.0

pkgs.ghdl-mcode

VHDL 2008/93/87 simulator

  • nixos-unstable -
    • nixos-unstable-small 6.0.0
  • nixos-26.05 -
    • nixos-26.05-small 6.0.0

pkgs.xtermcontrol

Enables dynamic control of xterm properties

  • nixos-unstable -
    • nixos-unstable-small 3.10
  • nixos-26.05 -
    • nixos-26.05-small 3.10

pkgs.mcontrolcenter

Tool to change the settings of MSI laptops running Linux

  • nixos-unstable -
    • nixos-unstable-small 0.5.1
  • nixos-26.05 -
    • nixos-26.05-small 0.5.1

pkgs.python313Packages.numcodecs

Buffer compression and transformation codecs for use in data storage and communication applications

  • nixos-unstable -
  • nixos-26.05 -

pkgs.python314Packages.numcodecs

Buffer compression and transformation codecs for use in data storage and communication applications

  • nixos-unstable -
  • nixos-26.05 -

pkgs.gnomeExtensions.streamcontroller-integration

Allow automatic page switching in StreamController by adding a dbus interface to fetch info about the current window.

  • nixos-unstable -
    • nixos-unstable-small 7
  • nixos-26.05 -
    • nixos-26.05-small 6