Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: matrix-appservice-discord

Found 3 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2026-100583
5.3 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 17 hours ago Activity log
  • Created suggestion
OpenClaw Discord before 2026.7.1 Authorization Bypass

OpenClaw Discord versions before 2026.7.1 contain an authorization bypass vulnerability in guild metadata read actions that allows lower-trust senders to retrieve information excluded by channel allowlists. Attackers can bypass the configured Discord read-target policy to access guild metadata from servers or channels outside the operator's allowlist.

Affected products

discord
  • ==2026.7.1
  • <2026.7.1

Matching in nixpkgs

pkgs.discord

All-in-one cross-platform voice and text chat for gamers

  • nixos-unstable -
  • nixos-26.05 -

pkgs.discord-sh

Write-only command-line Discord webhook integration written in 100% Bash script

  • nixos-unstable -
    • nixos-unstable-small 2.0.1
  • nixos-26.05 -
    • nixos-26.05-small 2.0.1

pkgs.discord-ptb

All-in-one cross-platform voice and text chat for gamers

  • nixos-unstable -
  • nixos-26.05 -

pkgs.discord-rpc

Official library to interface with the Discord client

  • nixos-unstable -
    • nixos-unstable-small 3.4.0
  • nixos-26.05 -
    • nixos-26.05-small 3.4.0

pkgs.discord-canary

All-in-one cross-platform voice and text chat for gamers

  • nixos-unstable -
  • nixos-26.05 -

pkgs.bitlbee-discord

Bitlbee plugin for Discord

  • nixos-unstable -
    • nixos-unstable-small 0.4.3
  • nixos-26.05 -
    • nixos-26.05-small 0.4.3

pkgs.discord-gamesdk

Library to allow other programs to interact with the Discord desktop application

  • nixos-unstable -
    • nixos-unstable-small 3.2.1
  • nixos-26.05 -
    • nixos-26.05-small 3.2.1

pkgs.mautrix-discord

Matrix-Discord puppeting bridge

  • nixos-unstable -
    • nixos-unstable-small 0.7.7
  • nixos-26.05 -
    • nixos-26.05-small 0.7.6

pkgs.mpd-discord-rpc

Rust application which displays your currently playing song / album / artist from MPD in Discord using Rich Presence

  • nixos-unstable -
  • nixos-26.05 -

pkgs.betterdiscordctl

Utility for managing BetterDiscord on Linux

  • nixos-unstable -
    • nixos-unstable-small 2.1.0
  • nixos-26.05 -
    • nixos-26.05-small 2.1.0

pkgs.music-discord-rpc

Cross-platform Discord rich presence for music with album cover and progress bar support

  • nixos-unstable -
    • nixos-unstable-small 0.7.0
  • nixos-26.05 -
    • nixos-26.05-small 0.7.0

pkgs.mpvScripts.mpv-discord

Cross-platform Discord Rich Presence integration for mpv with no external dependencies

  • nixos-unstable -
    • nixos-unstable-small 1.6.1
  • nixos-26.05 -
    • nixos-26.05-small 1.6.1
Untriaged
Permalink CVE-2026-100541
7.7 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated 11 hours ago by @symphorien Activity log
  • Created suggestion
  • @symphorien ignored
    13 packages
    • matrix-brandy
    • matrix-conduit
    • matrix-synapse
    • matrix-tuwunel
    • matrix-corporal
    • matrix-hookshot
    • weechat-matrix-rs
    • matrix-synapse-plugins.matrix-synapse-s3-storage-provider
    • matrix-synapse-plugins.matrix-synapse-shared-secret-auth
    • matrix-synapse-plugins.matrix-synapse-mjolnir-antispam
    • matrix-synapse-plugins.matrix-http-rendezvous-synapse
    • matrix-synapse-plugins.matrix-synapse-ldap3
    • matrix-synapse-plugins.matrix-synapse-pam
OpenClaw Matrix before 2026.8.1 Authorization Bypass via Case Folding

OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-name portion — when deriving the OpenClaw authorization identity. As a result, distinct authenticated Matrix accounts can normalize to the same authorization identity. A Matrix participant controlling a colliding account identifier (a protocol-valid identifier that differs from the configured one only by characters OpenClaw case/Unicode folds; display-name matching is not required) can inherit allowlist, owner-command, exec-approval, or plugin-approval authority configured for another account. The issue is fixed in 2026.8.1.

Affected products

matrix
  • <2026.8.1
  • ==2026.8.1

Matching in nixpkgs

pkgs.cmatrix

Simulates the falling characters theme from The Matrix movie

  • nixos-unstable -
    • nixos-unstable-small 2.0
  • nixos-26.05 -
    • nixos-26.05-small 2.0

pkgs.rmatrix

Digital rain for modern terminals

  • nixos-unstable -
    • nixos-unstable-small 0.3.3

pkgs.tmatrix

Terminal based replica of the digital rain from The Matrix

  • nixos-unstable -
    • nixos-unstable-small 1.4
  • nixos-26.05 -
    • nixos-26.05-small 1.4

pkgs.dendrite

Second-generation Matrix homeserver written in Go

  • nixos-unstable -
  • nixos-26.05 -

pkgs.gomatrix

Displays "The Matrix" in a terminal

  • nixos-unstable -
  • nixos-26.05 -

pkgs.libcmatrix

Matrix protocol library written in C using GObject

  • nixos-unstable -
    • nixos-unstable-small 0.0.4
  • nixos-26.05 -
    • nixos-26.05-small 0.0.4

pkgs.matrix-hook

Simple webhook for matrix

  • nixos-unstable -
    • nixos-unstable-small 1.0.0
  • nixos-26.05 -
    • nixos-26.05-small 1.0.0

pkgs.matrix-commander

Simple but convenient CLI-based Matrix client app for sending and receiving

  • nixos-unstable -
    • nixos-unstable-small 8.0.5
  • nixos-26.05 -
    • nixos-26.05-small 8.0.5

pkgs.matrix-media-repo

Highly configurable multi-domain media repository for Matrix

  • nixos-unstable -
    • nixos-unstable-small 1.3.8
  • nixos-26.05 -
    • nixos-26.05-small 1.3.8

pkgs.matrix-alertmanager

Bot to receive Alertmanager webhook events and forward them to chosen rooms

  • nixos-unstable -
  • nixos-26.05 -
    • nixos-26.05-small 0.9.0

pkgs.matrix-commander-rs

CLI-based Matrix client app for sending and receiving

  • nixos-unstable -
  • nixos-26.05 -
    • nixos-26.05-small 1.0.0

pkgs.matrix-continuwuity

Matrix homeserver written in Rust, forked from conduwuit

  • nixos-unstable -
  • nixos-26.05 -

pkgs.matrix-zulip-bridge

Matrix puppeting appservice bridge for Zulip

  • nixos-unstable -
    • nixos-unstable-small 0.4.1
  • nixos-26.05 -
    • nixos-26.05-small 0.4.1

pkgs.python313Packages.canmatrix

Support and convert several CAN (Controller Area Network) database formats

  • nixos-unstable -
    • nixos-unstable-small 1.2
  • nixos-26.05 -
    • nixos-26.05-small 1.2

pkgs.python314Packages.canmatrix

Support and convert several CAN (Controller Area Network) database formats

  • nixos-unstable -
    • nixos-unstable-small 1.2
  • nixos-26.05 -
    • nixos-26.05-small 1.2

pkgs.gnomeExtensions.workspace-matrix

Arrange workspaces in a two dimensional grid with workspace thumbnails.

  • nixos-unstable -
    • nixos-unstable-small 53
  • nixos-26.05 -
    • nixos-26.05-small 53
Ignored packages (13)

pkgs.matrix-brandy

Matrix Brandy BASIC VI for Linux, Windows, MacOSX

  • nixos-unstable -
  • nixos-26.05 -

pkgs.matrix-conduit

Matrix homeserver written in Rust

  • nixos-unstable -
  • nixos-26.05 -

pkgs.matrix-tuwunel

Matrix homeserver written in Rust, official successor to conduwuit

  • nixos-unstable -
    • nixos-unstable-small 1.9.2
  • nixos-26.05 -
    • nixos-26.05-small 1.9.1

pkgs.matrix-corporal

Reconciliator and gateway for a managed Matrix server

  • nixos-unstable -
    • nixos-unstable-small 2.2.0
  • nixos-26.05 -
    • nixos-26.05-small 2.2.0

pkgs.matrix-hookshot

Bridge between Matrix and multiple project management services, such as GitHub, GitLab and JIRA

  • nixos-unstable -
    • nixos-unstable-small 7.5.0
  • nixos-26.05 -
    • nixos-26.05-small 7.5.0

Package maintainers

Untriaged
Permalink CVE-2026-100526
6.0 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 17 hours ago Activity log
  • Created suggestion
Vulnerability in discord

OpenClaw's Discord integration (npm package @openclaw/discord) before version 2026.9.3 could lose the sender-scoped media policy in the emoji and sticker upload actions before loading a local file. A sender permitted to invoke those actions could cause OpenClaw to read a host path that the same sender's configured media roots would otherwise reject, placing bytes from an out-of-policy local file into an outbound emoji or sticker upload. Exploitation requires access to the guild asset action and knowledge or derivation of a useful local path; the issue does not permit unrestricted filesystem browsing or code execution. The issue is fixed in @openclaw/discord 2026.9.3.

Affected products

discord
  • <2026.9.3
  • ==2026.9.3

Matching in nixpkgs

pkgs.discord

All-in-one cross-platform voice and text chat for gamers

  • nixos-unstable -
  • nixos-26.05 -

pkgs.discord-sh

Write-only command-line Discord webhook integration written in 100% Bash script

  • nixos-unstable -
    • nixos-unstable-small 2.0.1
  • nixos-26.05 -
    • nixos-26.05-small 2.0.1

pkgs.discord-ptb

All-in-one cross-platform voice and text chat for gamers

  • nixos-unstable -
  • nixos-26.05 -

pkgs.discord-rpc

Official library to interface with the Discord client

  • nixos-unstable -
    • nixos-unstable-small 3.4.0
  • nixos-26.05 -
    • nixos-26.05-small 3.4.0

pkgs.discord-canary

All-in-one cross-platform voice and text chat for gamers

  • nixos-unstable -
  • nixos-26.05 -

pkgs.bitlbee-discord

Bitlbee plugin for Discord

  • nixos-unstable -
    • nixos-unstable-small 0.4.3
  • nixos-26.05 -
    • nixos-26.05-small 0.4.3

pkgs.discord-gamesdk

Library to allow other programs to interact with the Discord desktop application

  • nixos-unstable -
    • nixos-unstable-small 3.2.1
  • nixos-26.05 -
    • nixos-26.05-small 3.2.1

pkgs.mautrix-discord

Matrix-Discord puppeting bridge

  • nixos-unstable -
    • nixos-unstable-small 0.7.7
  • nixos-26.05 -
    • nixos-26.05-small 0.7.6

pkgs.mpd-discord-rpc

Rust application which displays your currently playing song / album / artist from MPD in Discord using Rich Presence

  • nixos-unstable -
  • nixos-26.05 -

pkgs.betterdiscordctl

Utility for managing BetterDiscord on Linux

  • nixos-unstable -
    • nixos-unstable-small 2.1.0
  • nixos-26.05 -
    • nixos-26.05-small 2.1.0

pkgs.music-discord-rpc

Cross-platform Discord rich presence for music with album cover and progress bar support

  • nixos-unstable -
    • nixos-unstable-small 0.7.0
  • nixos-26.05 -
    • nixos-26.05-small 0.7.0

pkgs.mpvScripts.mpv-discord

Cross-platform Discord Rich Presence integration for mpv with no external dependencies

  • nixos-unstable -
    • nixos-unstable-small 1.6.1
  • nixos-26.05 -
    • nixos-26.05-small 1.6.1