6.8 MEDIUM
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): High (H)
- Vulnerable System Impact Integrity (VI): None (N)
- Vulnerable System Impact Availability (VA): None (N)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): High (H)
- Modified Vulnerable System Impact Integrity (MVI): None (N)
- Modified Vulnerable System Impact Availability (MVA): None (N)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
by @erictapen Activity log
- Created suggestion
- @erictapen dismissed
Araxis Merge insufficiently protected credentials
Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the Windows registry and does not apply sufficient cryptographic protection. An authenticated, non-administrative attacker could retrieve and unencrypt all credentials the target user has stored in Merge.
References
Affected products
- ==2026.1
- <2026.1
Matching in nixpkgs
pkgs.nbmerge
Tool to merge/concatenate Jupyter (IPython) notebooks
pkgs.hdrmerge
Combines two or more raw images into an HDR
-
nixos-unstable -
- nixos-unstable-small 0.5.0-unstable-2025-04-26
-
nixos-26.05 -
- nixos-26.05-small 0.5.0-unstable-2025-04-26
pkgs.mergerfs
FUSE based union filesystem
pkgs.merge-fmt
Git mergetool leveraging code formatters
pkgs.vidmerger
Merge video & audio files via CLI
pkgs.git-imerge
Perform a merge between two branches incrementally
pkgs.yaml-merge
Merge YAML data files
-
nixos-unstable -
- nixos-unstable-small 0-unstable-2022-01-12
-
nixos-26.05 -
- nixos-26.05-small 0-unstable-2022-01-12
pkgs.cidr-merger
Simple command line tool to merge ip/ip cidr/ip range, supports IPv4/IPv6
pkgs.cudatoolkit
Wrapper substituting the deprecated runfile-based CUDA installation
pkgs.sublime-merge
Git client from the makers of Sublime Text
pkgs.mergerfs-tools
Optional tools to help manage data in a mergerfs pool
pkgs.git-when-merged
Helps you figure out when and why a commit was merged into a branch
pkgs.claude-mergetool
Resolve Git/jj merge conflicts automatically with claude-code
pkgs.freebsd.ctfmerge
None
-
nixos-unstable -
- nixos-unstable-small 15.0.0
pkgs.sublime-merge-dev
Git client from the makers of Sublime Text
pkgs.haskellPackages.merge
A functor for consistent merging of information
pkgs.perlPackages.HashMerge
Merges arbitrarily deep hashes into a single hash
pkgs.perl5Packages.HashMerge
Merges arbitrarily deep hashes into a single hash
pkgs.cudaPackages.cudatoolkit
Wrapper substituting the deprecated runfile-based CUDA installation
pkgs.haskellPackages.mergeful
None
pkgs.perlPackages.ConfigMerge
Load a configuration directory tree containing YAML, JSON, XML, Perl, INI or Config::General files
pkgs.python313Packages.emerge
Electromagnetic field computation program
-
nixos-unstable -
- nixos-unstable-small 2.8.9
pkgs.python313Packages.merge3
Python implementation of 3-way merge
pkgs.python314Packages.emerge
Electromagnetic field computation program
-
nixos-unstable -
- nixos-unstable-small 2.8.9
pkgs.python314Packages.merge3
Python implementation of 3-way merge
pkgs.haskellPackages.mergeless
None
pkgs.perl5Packages.ConfigMerge
Load a configuration directory tree containing YAML, JSON, XML, Perl, INI or Config::General files
pkgs.python313Packages.mergedb
Tool/library for deep merging YAML files
pkgs.python314Packages.mergedb
Tool/library for deep merging YAML files
pkgs.git-delete-merged-branches
Command-line tool to delete merged Git branches
pkgs.python313Packages.mergecal
None
pkgs.python313Packages.ufomerge
Command line utility and Python library that merges two UFO source format fonts into a single file
pkgs.python314Packages.mergecal
None
pkgs.python314Packages.ufomerge
Command line utility and Python library that merges two UFO source format fonts into a single file
-
nixos-unstable -
- nixos-unstable-small 1.9.8
pkgs.haskellPackages.apply-merge
Lift a binary, non-decreasing function onto ordered lists and order the output
pkgs.perlPackages.AlgorithmMerge
Three-way merge and diff
pkgs.python313Packages.deepmerge
Toolset to deeply merge python dictionaries
pkgs.python313Packages.jsonmerge
Merge a series of JSON documents
pkgs.python313Packages.mergedeep
Deep merge function for python
pkgs.python313Packages.mergedict
Python dict with a merge() method
pkgs.python314Packages.deepmerge
Toolset to deeply merge python dictionaries
pkgs.python314Packages.jsonmerge
Merge a series of JSON documents
pkgs.python314Packages.mergedeep
Deep merge function for python
pkgs.python314Packages.mergedict
Python dict with a merge() method
pkgs.perl5Packages.AlgorithmMerge
Three-way merge and diff
pkgs.perlPackages.HashMergeSimple
Recursively merge two or more hashes, simply
pkgs.haskellPackages.conduit-merge
Merge multiple sorted conduits
pkgs.perl5Packages.HashMergeSimple
Recursively merge two or more hashes, simply
pkgs.python313Packages.three-merge
Simple library for merging two strings with respect to a base one
pkgs.python314Packages.three-merge
Simple library for merging two strings with respect to a base one
pkgs.haskellPackages.merge-bash-history
command line utility to merge bash_history
pkgs.pidginPackages.pidgin-window-merge
Pidgin plugin that merges the Buddy List window with a conversation window
pkgs.python313Packages.json-merge-patch
JSON Merge Patch library
pkgs.python314Packages.json-merge-patch
JSON Merge Patch library
pkgs.haskellPackages.mergeless-persistent
Support for using mergeless from persistent-based databases
pkgs.haskellPackages.genvalidity-mergeless
None
Package maintainers
-
@cyounkins Craig Younkins <cyounkins@gmail.com>
-
@9999years Rebecca Turner <rbt@fastmail.com>
-
@GaetanLepage Gaetan Lepage <gaetan@glepage.com>
-
@SomeoneSerge Else Someone <else+nixpkgs@someonex.net>
-
@ConnorBaker Connor Baker <ConnorBaker01@gmail.com>
-
@ethancedwards8 Ethan Carter Edwards <ethan@ethancedwards.com>
-
@samuela Samuel Ainsworth <skainsworth@gmail.com>
-
@prusnak Pavol Rusnak <pavol@rusnak.io>
-
@YorikSar Yuriy Taraday <yorik.sar@gmail.com>
-
@artemist Artemis Tosini <me@artem.ist>
-
@rhelmot Audrey Dutcher <audrey@rhelmot.io>
-
@SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com>
-
@DamienCassou Damien Cassou <damien@cassou.me>
-
@paperdigits Mica Semrick <mica@silentumbrella.com>
-
@Alizter Ali Caglayan <alizter@gmail.com>
-
@makefu Felix Richter <makefu@syntax-fehler.de>
-
@mweinelt Martin Weinelt <hexa@darmstadt.ccc.de>
-
@eljamm Fedi Jamoussi <fedi.jamoussi@protonmail.ch>
-
@Prince213 Sizhe Zhao <prc.zhao@outlook.com>
-
@phanirithvij Phani Rithvij <phanirithvij2000@gmail.com>
-
@erictapen Kerstin Humm <kerstin@erictapen.name>
-
@graysonhead Grayson Head <grayson@graysonhead.net>
-
@risicle Robert Scott <code@humanleg.org.uk>
-
@onny Jonas Heinrich <onny@project-insanity.org>
-
@jopejoe1 jopejoe1 <nixpkgs@missing.ninja>
-
@zookatron Tim Zook <tim@zookatron.com>
-
@ByteSudoer ByteSudoer <bytesudoer@gmail.com>