Nixpkgs security tracker

Login with GitHub

Suggestions search

With package: python314Packages.gmsh

Found 5 matching suggestions

View:
Compact
Detailed
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-66145
9.1 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 3 weeks, 6 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
An unauthenticated remote code execution vulnerability was identified in GMS …

An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.

Affected products

GMS
  • ==9.5.1 and earlier versions

Matching in nixpkgs

pkgs.gmsh

Three-dimensional finite element mesh generator

pkgs.vgmstream

Library for playback of various streamed audio formats used in video games

  • nixos-unstable 2117
    • nixpkgs-unstable 2117
    • nixos-unstable-small 2117
  • nixos-26.05 2117
    • nixos-26.05-small 2117
    • nixpkgs-26.05-darwin 2117

pkgs.x42-gmsynth

Chris Colins' General User soundfont player LV2 plugin

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-66148
6.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 3 weeks, 6 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
An authenticated command injection vulnerability was identified in GMS Command-Line …

An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions which allows low-privileged local user to execute system commands with root privileges.

Affected products

GMS
  • ==9.5.1 and earlier versions

Matching in nixpkgs

pkgs.gmsh

Three-dimensional finite element mesh generator

pkgs.vgmstream

Library for playback of various streamed audio formats used in video games

  • nixos-unstable 2117
    • nixpkgs-unstable 2117
    • nixos-unstable-small 2117
  • nixos-26.05 2117
    • nixos-26.05-small 2117
    • nixpkgs-26.05-darwin 2117

pkgs.x42-gmsynth

Chris Colins' General User soundfont player LV2 plugin

Dismissed
(not in Nixpkgs)
updated 3 weeks, 6 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
An insecure handling of serialized objects vulnerability was found in …

An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier versions. A local attacker with the ability to interact with the service could exploit this behavior to perform unauthorized actions through the affected component.

Affected products

GMS
  • ==9.5.1 and earlier versions

Matching in nixpkgs

pkgs.gmsh

Three-dimensional finite element mesh generator

pkgs.vgmstream

Library for playback of various streamed audio formats used in video games

  • nixos-unstable 2117
    • nixpkgs-unstable 2117
    • nixos-unstable-small 2117
  • nixos-26.05 2117
    • nixos-26.05-small 2117
    • nixpkgs-26.05-darwin 2117

pkgs.x42-gmsynth

Chris Colins' General User soundfont player LV2 plugin

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-66154
8.3 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Adjacent (A)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Adjacent (A)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 3 weeks, 6 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
An insufficient certificate validation in a privileged communication workflow, was …

An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlier versions which, under a successful MitM attack and controlled network conditions, could permit unauthorized changes.

Affected products

GMS
  • ==9.5.1 and earlier versions

Matching in nixpkgs

pkgs.gmsh

Three-dimensional finite element mesh generator

pkgs.vgmstream

Library for playback of various streamed audio formats used in video games

  • nixos-unstable 2117
    • nixpkgs-unstable 2117
    • nixos-unstable-small 2117
  • nixos-26.05 2117
    • nixos-26.05-small 2117
    • nixpkgs-26.05-darwin 2117

pkgs.x42-gmsynth

Chris Colins' General User soundfont player LV2 plugin

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-66146
6.1 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 3 weeks, 6 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 …

Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker to execute javascript script in a user's browser.

Affected products

GMS
  • ==9.5.1 and earlier versions

Matching in nixpkgs

pkgs.gmsh

Three-dimensional finite element mesh generator

pkgs.vgmstream

Library for playback of various streamed audio formats used in video games

  • nixos-unstable 2117
    • nixpkgs-unstable 2117
    • nixos-unstable-small 2117
  • nixos-26.05 2117
    • nixos-26.05-small 2117
    • nixpkgs-26.05-darwin 2117

pkgs.x42-gmsynth

Chris Colins' General User soundfont player LV2 plugin