Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: pkgsRocm.lms

Found 3 matching suggestions

View:
Compact
Detailed
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-54343
8.7 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated 5 days, 12 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Frappe LMS: Path Traversal in SCORM File Serving

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.52.1, a remote attacker can request a traversal path handled by SCORMRenderer.render in lms/page_renderers.py. The renderer constructs and opens a server-side path without first confirming that its real path remains within public/scorm, allowing files outside the SCORM directory to be read when they are accessible to the server process. This issue is fixed in version 2.52.1.

Affected products

lms
  • ==< 2.52.1

Matching in nixpkgs

pkgs.lms

Lightweight Music Server - Access your self-hosted music using a web interface

pkgs.helmsman

Helm Charts (k8s applications) as Code tool

pkgs.lmstudio

LM Studio is an easy to use desktop app for experimenting with local and open-source Large Language Models (LLMs)

pkgs.pkgsRocm.lms

Lightweight Music Server - Access your self-hosted music using a web interface

  • nixos-unstable -

pkgs.lmstudio-bionic

Bionic is an easy to use desktop app for experimenting with local and open-source Large Language Models (LLMs)

  • nixos-unstable -

Package maintainers

Untriaged
Permalink CVE-2026-39385
7.1 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 months ago Activity log
  • Created suggestion
Frappe LMS enrollment bypass in paid courses via unrelated batch

Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course.

Affected products

lms
  • ==<= 2.51.0

Matching in nixpkgs

pkgs.lms

Lightweight Music Server - Access your self-hosted music using a web interface

  • nixos-unstable -
  • nixos-26.05 -

pkgs.flmsg

Digital modem message program

  • nixos-unstable -
  • nixos-26.05 -

pkgs.helmsman

Helm Charts (k8s applications) as Code tool

  • nixos-unstable -
    • nixos-unstable-small 4.0.5
  • nixos-26.05 -
    • nixos-26.05-small 4.0.5

pkgs.llmserve

TUI for serving local LLM models

  • nixos-unstable -
  • nixos-26.05 -
    • nixos-26.05-small 0.0.8

pkgs.lmstudio

LM Studio is an easy to use desktop app for experimenting with local and open-source Large Language Models (LLMs)

  • nixos-unstable -
  • nixos-26.05 -

pkgs.pkgsRocm.lms

Lightweight Music Server - Access your self-hosted music using a web interface

  • nixos-unstable -

pkgs.lmstudio-bionic

Bionic is an easy to use desktop app for experimenting with local and open-source Large Language Models (LLMs)

  • nixos-unstable -

Package maintainers

Untriaged
created 5 months, 2 weeks ago Activity log
  • Created suggestion
Stored XSS in Frappe LMS

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. From version 2.27.0 to before version 2.48.0, Frappe LMS was vulnerable to stored XSS. This issue has been patched in version 2.48.0.

Affected products

lms
  • ==>= 2.27.0, < 2.48.0

Matching in nixpkgs

pkgs.lms

Lightweight Music Server - Access your self-hosted music using a web interface

  • nixos-unstable -
  • nixos-26.05 -

pkgs.flmsg

Digital modem message program

  • nixos-unstable -
  • nixos-26.05 -

pkgs.helmsman

Helm Charts (k8s applications) as Code tool

  • nixos-unstable -
    • nixos-unstable-small 4.0.5
  • nixos-26.05 -
    • nixos-26.05-small 4.0.5

pkgs.llmserve

TUI for serving local LLM models

  • nixos-unstable -
  • nixos-26.05 -
    • nixos-26.05-small 0.0.8

pkgs.lmstudio

LM Studio is an easy to use desktop app for experimenting with local and open-source Large Language Models (LLMs)

  • nixos-unstable -
  • nixos-26.05 -

pkgs.pkgsRocm.lms

Lightweight Music Server - Access your self-hosted music using a web interface

  • nixos-unstable -

pkgs.lmstudio-bionic

Bionic is an easy to use desktop app for experimenting with local and open-source Large Language Models (LLMs)

  • nixos-unstable -

Package maintainers