Nixpkgs security tracker

Login with GitHub

Suggestions search

With package: python313Packages.kiwiki-client

Found 1 matching suggestions

View:
Compact
Detailed
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-55630
0.0 NONE
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 3 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Kiwi TCMS: Stored XSS via javascript: URI in extra_link field (TestPlan & TestCase)

Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted unsanitized user input and rendered stored values verbatim, creating an opportunity for cross-site scripting. Official Docker images and unmodified Kiwi TCMS middleware send a Content-Security-Policy header that blocks inline JavaScript, making exploitation difficult in default deployments, while customized deployments that weaken those security settings may remain vulnerable. Version 16.1 properly sanitizes both fields and resets existing database records that do not validate to null. This issue is fixed in version 16.1.

Affected products

Kiwi
  • ==< 16.1

Matching in nixpkgs

pkgs.kiwix

Offline reader for Web content

pkgs.gnomeExtensions.kiwi-menu

macOS-inspired quick menu for GNOME

  • nixos-unstable 22
    • nixpkgs-unstable 22
    • nixos-unstable-small 33
  • nixos-26.05 22
    • nixos-26.05-small 22
    • nixpkgs-26.05-darwin 22

pkgs.gnomeExtensions.kiwi-is-not-apple

Kiwi is free open source project that brings macOS-inspired features for GNOME.

  • nixos-unstable 43
    • nixpkgs-unstable 43
    • nixos-unstable-small 50
  • nixos-26.05 43
    • nixos-26.05-small 43
    • nixpkgs-26.05-darwin 43

Package maintainers