Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: python313Packages.pymsteams

Found 4 matching suggestions

View:
Compact
Detailed
Permalink CVE-2026-100582
7.1 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated 2 days, 14 hours ago by @symphorien Activity log
  • Created suggestion
  • @symphorien ignored
    41 packages
    • cmatrix
    • rmatrix
    • tmatrix
    • dendrite
    • gomatrix
    • matrix-dl
    • matrix-synapse-plugins.matrix-synapse-s3-storage-provider
    • matrix-synapse-plugins.matrix-synapse-shared-secret-auth
    • matrix-synapse-plugins.matrix-synapse-mjolnir-antispam
    • matrix-synapse-plugins.matrix-http-rendezvous-synapse
    • matrix-synapse-plugins.matrix-synapse-ldap3
    • matrix-synapse-plugins.matrix-synapse-pam
    • unimatrix
    • libcmatrix
    • matrix-hook
    • matrix-brandy
    • matrix-conduit
    • matrix-synapse
    • matrix-tuwunel
    • matrix-hookshot
    • kodiPackages.six
    • matrix-gtk-theme
    • weechat-matrix-rs
    • mautrix-googlechat
    • kodiPackages.future
    • kodiPackages.upnext
    • matrix-alertmanager
    • matrix-commander-rs
    • matrix-continuwuity
    • matrix-zulip-bridge
    • kodiPackages.routing
    • kodiPackages.signals
    • matrix-appservice-irc
    • kodiPackages.defusedxml
    • haskellPackages.hmatrix
    • matrix-appservice-discord
    • haskellPackages.hmatrix-gsl
    • haskellPackages.hmatrix-csv
    • python313Packages.matrix-nio
    • python314Packages.matrix-nio
    • weechatScripts.weechat-matrix-bridge
OpenClaw Channel Plugins before 2026.8.1 Channel Read Allowlist Bypass

OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8.1 do not enforce the configured channel read allowlist for caller-supplied explicit read targets in message, reaction, pin, member, and related metadata read actions. A lower-trust sender or a steered agent with access to a channel read action can therefore retrieve content or metadata from channels or rooms excluded by the operator's read policy; the practical impact depends on the permissions held by the connected bot account. The issue is fixed in 2026.8.1.

Affected products

feishu
  • <2026.8.1
  • ==2026.8.1
matrix
  • <2026.8.1
  • ==2026.8.1
msteams
  • <2026.8.1
  • ==2026.8.1
googlechat
  • <2026.8.1
  • ==2026.8.1

Matching in nixpkgs

pkgs.feishu

All-in-one collaboration suite

  • nixos-unstable -
  • nixos-26.05 -

pkgs.feishu-cli

CLI for Feishu (Lark) Open Platform

  • nixos-unstable -
  • nixos-26.05 -

pkgs.matrix-corporal

Reconciliator and gateway for a managed Matrix server

  • nixos-unstable -
    • nixos-unstable-small 2.2.0
  • nixos-26.05 -
    • nixos-26.05-small 2.2.0

pkgs.matrix-commander

Simple but convenient CLI-based Matrix client app for sending and receiving

  • nixos-unstable -
    • nixos-unstable-small 8.0.5
  • nixos-26.05 -
    • nixos-26.05-small 8.0.5

pkgs.matrix-media-repo

Highly configurable multi-domain media repository for Matrix

  • nixos-unstable -
    • nixos-unstable-small 1.3.8
  • nixos-26.05 -
    • nixos-26.05-small 1.3.8

pkgs.matrix-sdk-crypto-nodejs

No-network-IO implementation of a state machine that handles E2EE for Matrix clients

  • nixos-unstable -
    • nixos-unstable-small 0.6.6
  • nixos-26.05 -

pkgs.python313Packages.canmatrix

Support and convert several CAN (Controller Area Network) database formats

  • nixos-unstable -
    • nixos-unstable-small 1.2
  • nixos-26.05 -
    • nixos-26.05-small 1.2

pkgs.python314Packages.canmatrix

Support and convert several CAN (Controller Area Network) database formats

  • nixos-unstable -
    • nixos-unstable-small 1.2
  • nixos-26.05 -
    • nixos-26.05-small 1.2

pkgs.gnomeExtensions.workspace-matrix

Arrange workspaces in a two dimensional grid with workspace thumbnails.

  • nixos-unstable -
    • nixos-unstable-small 53
  • nixos-26.05 -
    • nixos-26.05-small 53
Ignored packages (41)

pkgs.cmatrix

Simulates the falling characters theme from The Matrix movie

  • nixos-unstable -
    • nixos-unstable-small 2.0
  • nixos-26.05 -
    • nixos-26.05-small 2.0

pkgs.rmatrix

Digital rain for modern terminals

  • nixos-unstable -
    • nixos-unstable-small 0.3.3

pkgs.tmatrix

Terminal based replica of the digital rain from The Matrix

  • nixos-unstable -
    • nixos-unstable-small 1.4
  • nixos-26.05 -
    • nixos-26.05-small 1.4

pkgs.dendrite

Second-generation Matrix homeserver written in Go

  • nixos-unstable -
  • nixos-26.05 -

pkgs.gomatrix

Displays "The Matrix" in a terminal

  • nixos-unstable -
  • nixos-26.05 -

pkgs.libcmatrix

Matrix protocol library written in C using GObject

  • nixos-unstable -
    • nixos-unstable-small 0.0.4
  • nixos-26.05 -
    • nixos-26.05-small 0.0.4

pkgs.matrix-hook

Simple webhook for matrix

  • nixos-unstable -
    • nixos-unstable-small 1.0.0
  • nixos-26.05 -
    • nixos-26.05-small 1.0.0

pkgs.matrix-brandy

Matrix Brandy BASIC VI for Linux, Windows, MacOSX

  • nixos-unstable -
  • nixos-26.05 -

pkgs.matrix-conduit

Matrix homeserver written in Rust

  • nixos-unstable -
  • nixos-26.05 -

pkgs.matrix-tuwunel

Matrix homeserver written in Rust, official successor to conduwuit

  • nixos-unstable -
    • nixos-unstable-small 1.9.3
  • nixos-26.05 -
    • nixos-26.05-small 1.9.1

pkgs.matrix-hookshot

Bridge between Matrix and multiple project management services, such as GitHub, GitLab and JIRA

  • nixos-unstable -
    • nixos-unstable-small 7.5.0
  • nixos-26.05 -
    • nixos-26.05-small 7.5.0

pkgs.mautrix-googlechat

Matrix-Google Chat puppeting bridge

  • nixos-unstable -
    • nixos-unstable-small 0.5.2
  • nixos-26.05 -
    • nixos-26.05-small 0.5.2

pkgs.matrix-alertmanager

Bot to receive Alertmanager webhook events and forward them to chosen rooms

  • nixos-unstable -
  • nixos-26.05 -
    • nixos-26.05-small 0.9.0

pkgs.matrix-commander-rs

CLI-based Matrix client app for sending and receiving

  • nixos-unstable -
  • nixos-26.05 -
    • nixos-26.05-small 1.0.0

pkgs.matrix-continuwuity

Matrix homeserver written in Rust, forked from conduwuit

  • nixos-unstable -
  • nixos-26.05 -

pkgs.matrix-zulip-bridge

Matrix puppeting appservice bridge for Zulip

  • nixos-unstable -
    • nixos-unstable-small 0.4.1
  • nixos-26.05 -
    • nixos-26.05-small 0.4.1
Permalink CVE-2026-62213
6.0 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 months, 1 week ago Activity log
  • Created suggestion
OpenClaw < 2026.5.27 Token Leakage via MS Teams Outbound Requests

OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot Framework tokens. Attackers can access configured input paths to retrieve credentials that should remain within the trusted boundary.

Affected products

msteams
  • <2026.5.27
  • ==2026.5.27

Matching in nixpkgs

Permalink CVE-2026-62214
6.0 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 months, 1 week ago Activity log
  • Created suggestion
OpenClaw < 2026.5.28 Bot Framework SSRF via serviceUrl Parameter Validation

OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-trust callers to expose bot tokens and credentials by failing to properly validate serviceUrl parameters. Attackers can supply malicious serviceUrl values through configured input paths to retrieve sensitive authentication data outside the trusted boundary.

Affected products

msteams
  • <2026.5.28
  • ==2026.5.28

Matching in nixpkgs

Permalink CVE-2026-62224
2.3 LOW
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 months, 1 week ago Activity log
  • Created suggestion
OpenClaw MS Teams < 2026.5.12 Authorization Bypass

OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mutable display names. Attackers with lower-trust access can perform actions requiring stronger authorization by exploiting the mutable display name binding in the affected feature.

Affected products

msteams
  • <2026.5.12
  • ==2026.5.12

Matching in nixpkgs