Nixpkgs security tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Permalink CVE-2026-47128
6.1 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): Low (L)
updated 6 days, 10 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    25 packages
    • mononoki
    • gnonograms
    • nerd-fonts.mononoki
    • maple-mono.Normal-CN
    • maple-mono.Normal-NF
    • maple-mono.Normal-OTF
    • maple-mono.Normal-TTF
    • maple-mono.NormalNL-CN
    • maple-mono.NormalNL-NF
    • maple-mono.Normal-NF-CN
    • maple-mono.Normal-Woff2
    • maple-mono.NormalNL-OTF
    • maple-mono.NormalNL-TTF
    • maple-mono.NormalNL-NF-CN
    • maple-mono.NormalNL-Woff2
    • maple-mono.Normal-Variable
    • maple-mono.NormalNL-Variable
    • maple-mono.Normal-CN-unhinted
    • maple-mono.Normal-NF-unhinted
    • maple-mono.Normal-TTF-AutoHint
    • maple-mono.NormalNL-CN-unhinted
    • maple-mono.NormalNL-NF-unhinted
    • maple-mono.Normal-NF-CN-unhinted
    • maple-mono.NormalNL-TTF-AutoHint
    • maple-mono.NormalNL-NF-CN-unhinted
  • @LeSuisse dismissed
nono: Sandbox escape on Linux via D-Bus: `systemd-run --user`

nono is software that allows users to run AI agents in a zero-latency sandbox. Prior to version 0.55.0, the nono Landlock/seccomp policies allow access to local Unix domain sockets (concrete and abstract). This allows an easy sandbox escape by talking to the per-user systemd dbus socket. Version 0.55.0 patches the issue.

Affected products

nono
  • ==< 0.55.0

Matching in nixpkgs

pkgs.nono

Secure, kernel-enforced sandbox for AI agents, MCP and LLM workloads

Ignored packages (25)

pkgs.mononoki

Font for programming and code review

  • nixos-unstable 1.6
    • nixpkgs-unstable 1.6
    • nixos-unstable-small 1.6
  • nixos-26.05 1.6
    • nixos-26.05-small 1.6
    • nixpkgs-26.05-darwin 1.6

pkgs.maple-mono.Normal-CN

Open source Normal Ligature monospace CN font with round corner and ligatures for IDE and command line

  • nixos-unstable 7.9
    • nixpkgs-unstable 7.9
    • nixos-unstable-small 7.9
  • nixos-26.05 7.9
    • nixos-26.05-small 7.9
    • nixpkgs-26.05-darwin 7.9

pkgs.maple-mono.Normal-NF

Open source Normal Ligature Nerd Font font with round corner and ligatures for IDE and command line

  • nixos-unstable 7.9
    • nixpkgs-unstable 7.9
    • nixos-unstable-small 7.9
  • nixos-26.05 7.9
    • nixos-26.05-small 7.9
    • nixpkgs-26.05-darwin 7.9

pkgs.maple-mono.Normal-OTF

Open source Normal Ligature OpenType font with round corner and ligatures for IDE and command line

  • nixos-unstable 7.9
    • nixpkgs-unstable 7.9
    • nixos-unstable-small 7.9
  • nixos-26.05 7.9
    • nixos-26.05-small 7.9
    • nixpkgs-26.05-darwin 7.9

pkgs.maple-mono.Normal-TTF

Open source Normal Ligature monospace TrueType font with round corner and ligatures for IDE and command line

  • nixos-unstable 7.9
    • nixpkgs-unstable 7.9
    • nixos-unstable-small 7.9
  • nixos-26.05 7.9
    • nixos-26.05-small 7.9
    • nixpkgs-26.05-darwin 7.9

pkgs.maple-mono.NormalNL-CN

Open source Normal No Ligature monospace CN font with round corner and ligatures for IDE and command line

  • nixos-unstable 7.9
    • nixpkgs-unstable 7.9
    • nixos-unstable-small 7.9
  • nixos-26.05 7.9
    • nixos-26.05-small 7.9
    • nixpkgs-26.05-darwin 7.9

pkgs.maple-mono.NormalNL-NF

Open source Normal No Ligature Nerd Font font with round corner and ligatures for IDE and command line

  • nixos-unstable 7.9
    • nixpkgs-unstable 7.9
    • nixos-unstable-small 7.9
  • nixos-26.05 7.9
    • nixos-26.05-small 7.9
    • nixpkgs-26.05-darwin 7.9

pkgs.maple-mono.Normal-NF-CN

Open source Normal Ligature Nerd Font CN font with round corner and ligatures for IDE and command line

  • nixos-unstable 7.9
    • nixpkgs-unstable 7.9
    • nixos-unstable-small 7.9
  • nixos-26.05 7.9
    • nixos-26.05-small 7.9
    • nixpkgs-26.05-darwin 7.9

pkgs.maple-mono.Normal-Woff2

Open source Normal Ligature WOFF2.0 font with round corner and ligatures for IDE and command line

  • nixos-unstable 7.9
    • nixpkgs-unstable 7.9
    • nixos-unstable-small 7.9
  • nixos-26.05 7.9
    • nixos-26.05-small 7.9
    • nixpkgs-26.05-darwin 7.9

pkgs.maple-mono.NormalNL-OTF

Open source Normal No Ligature OpenType font with round corner and ligatures for IDE and command line

  • nixos-unstable 7.9
    • nixpkgs-unstable 7.9
    • nixos-unstable-small 7.9
  • nixos-26.05 7.9
    • nixos-26.05-small 7.9
    • nixpkgs-26.05-darwin 7.9

pkgs.maple-mono.NormalNL-TTF

Open source Normal No Ligature monospace TrueType font with round corner and ligatures for IDE and command line

  • nixos-unstable 7.9
    • nixpkgs-unstable 7.9
    • nixos-unstable-small 7.9
  • nixos-26.05 7.9
    • nixos-26.05-small 7.9
    • nixpkgs-26.05-darwin 7.9

pkgs.maple-mono.NormalNL-NF-CN

Open source Normal No Ligature Nerd Font CN font with round corner and ligatures for IDE and command line

  • nixos-unstable 7.9
    • nixpkgs-unstable 7.9
    • nixos-unstable-small 7.9
  • nixos-26.05 7.9
    • nixos-26.05-small 7.9
    • nixpkgs-26.05-darwin 7.9

pkgs.maple-mono.NormalNL-Woff2

Open source Normal No Ligature WOFF2.0 font with round corner and ligatures for IDE and command line

  • nixos-unstable 7.9
    • nixpkgs-unstable 7.9
    • nixos-unstable-small 7.9
  • nixos-26.05 7.9
    • nixos-26.05-small 7.9
    • nixpkgs-26.05-darwin 7.9

pkgs.maple-mono.Normal-Variable

Open source Normal Ligature monospace variable font with round corner and ligatures for IDE and command line

  • nixos-unstable 7.9
    • nixpkgs-unstable 7.9
    • nixos-unstable-small 7.9
  • nixos-26.05 7.9
    • nixos-26.05-small 7.9
    • nixpkgs-26.05-darwin 7.9

pkgs.maple-mono.NormalNL-Variable

Open source Normal No Ligature monospace variable font with round corner and ligatures for IDE and command line

  • nixos-unstable 7.9
    • nixpkgs-unstable 7.9
    • nixos-unstable-small 7.9
  • nixos-26.05 7.9
    • nixos-26.05-small 7.9
    • nixpkgs-26.05-darwin 7.9

pkgs.maple-mono.Normal-CN-unhinted

Open source Normal Ligature monospace CN unhinted font with round corner and ligatures for IDE and command line

  • nixos-unstable 7.9
    • nixpkgs-unstable 7.9
    • nixos-unstable-small 7.9
  • nixos-26.05 7.9
    • nixos-26.05-small 7.9
    • nixpkgs-26.05-darwin 7.9

pkgs.maple-mono.Normal-NF-unhinted

Open source Normal Ligature Nerd Font unhinted font with round corner and ligatures for IDE and command line

  • nixos-unstable 7.9
    • nixpkgs-unstable 7.9
    • nixos-unstable-small 7.9
  • nixos-26.05 7.9
    • nixos-26.05-small 7.9
    • nixpkgs-26.05-darwin 7.9

pkgs.maple-mono.Normal-TTF-AutoHint

Open source Normal Ligature monospace ttf autohint font with round corner and ligatures for IDE and command line

  • nixos-unstable 7.9
    • nixpkgs-unstable 7.9
    • nixos-unstable-small 7.9
  • nixos-26.05 7.9
    • nixos-26.05-small 7.9
    • nixpkgs-26.05-darwin 7.9

pkgs.maple-mono.NormalNL-CN-unhinted

Open source Normal No Ligature monospace CN unhinted font with round corner and ligatures for IDE and command line

  • nixos-unstable 7.9
    • nixpkgs-unstable 7.9
    • nixos-unstable-small 7.9
  • nixos-26.05 7.9
    • nixos-26.05-small 7.9
    • nixpkgs-26.05-darwin 7.9

pkgs.maple-mono.NormalNL-NF-unhinted

Open source Normal No Ligature Nerd Font unhinted font with round corner and ligatures for IDE and command line

  • nixos-unstable 7.9
    • nixpkgs-unstable 7.9
    • nixos-unstable-small 7.9
  • nixos-26.05 7.9
    • nixos-26.05-small 7.9
    • nixpkgs-26.05-darwin 7.9

pkgs.maple-mono.Normal-NF-CN-unhinted

Open source Normal Ligature Nerd Font CN unhinted font with round corner and ligatures for IDE and command line

  • nixos-unstable 7.9
    • nixpkgs-unstable 7.9
    • nixos-unstable-small 7.9
  • nixos-26.05 7.9
    • nixos-26.05-small 7.9
    • nixpkgs-26.05-darwin 7.9

pkgs.maple-mono.NormalNL-TTF-AutoHint

Open source Normal No Ligature monospace ttf autohint font with round corner and ligatures for IDE and command line

  • nixos-unstable 7.9
    • nixpkgs-unstable 7.9
    • nixos-unstable-small 7.9
  • nixos-26.05 7.9
    • nixos-26.05-small 7.9
    • nixpkgs-26.05-darwin 7.9

pkgs.maple-mono.NormalNL-NF-CN-unhinted

Open source Normal No Ligature Nerd Font CN unhinted font with round corner and ligatures for IDE and command line

  • nixos-unstable 7.9
    • nixpkgs-unstable 7.9
    • nixos-unstable-small 7.9
  • nixos-26.05 7.9
    • nixos-26.05-small 7.9
    • nixpkgs-26.05-darwin 7.9

Package maintainers

Current stable branch was never impacted
Permalink CVE-2026-26080
3.7 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 6 days, 10 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    2 packages
    • prometheus-haproxy-exporter
    • haskellPackages.io-streams-haproxy
  • @LeSuisse dismissed
HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter …

HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.

Affected products

HAProxy
  • <3.2.12
  • <3.3.3

Matching in nixpkgs

pkgs.haproxy

Reliable, high performance TCP/HTTP load balancer

Ignored packages (2)

Package maintainers

Current stable branch was never impacted
Permalink CVE-2026-54685
5.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 6 days, 10 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • python313Packages.filebrowser-safe
    • python314Packages.filebrowser-safe
    • filebrowser
  • @LeSuisse dismissed
FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the `/api/auth/login` authentication endpoint does not execute in constant time. When a non-existent username is supplied, the server returns a `401`/`403` response almost immediately. When a valid username is provided, the server performs a bcrypt password comparison, causing a measurable delay in the response time. Version 1.3.2-beta patches the issue.

Affected products

filebrowser
  • ==< 1.3.2-beta

Matching in nixpkgs

Ignored packages (3)

Package maintainers

Current stable branch was never impacted
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-16211
1.2 LOW
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Adjacent (A)
  • Attack Complexity (AC): High (H)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Exploit Maturity (E): POC (P)
  • Modified Attack Vector (MAV): Adjacent (A)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
updated 6 days, 10 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package sbclPackages.cl-liballegro-nuklear
  • @LeSuisse dismissed (not in Nixpkgs)
allegro Hostname Allocation assets.py AssetLastHostname.increment_hostname race condition

A vulnerability was determined in allegro up to bcf65b994ef29fb3fc2e10b660e6288723d5209e. This impacts the function AssetLastHostname.increment_hostname of the file src/ralph/assets/models/assets.py of the component Hostname Allocation Handler. Executing a manipulation of the argument counter can lead to race condition. Attacks of this nature are highly complex. The exploitability is said to be difficult. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

allegro
  • ==bcf65b994ef29fb3fc2e10b660e6288723d5209e

Matching in nixpkgs

Ignored packages (1)

Package maintainers

Permalink CVE-2026-53594
4.9 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 6 days, 10 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed
FreeScout has Arbitrary File Read in App Logs Viewer via Forged Encrypted Path

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. FreeScout's `Manage -> Logs -> App Logs` feature uses the bundled `rap2hpoutre/laravel-log-viewer` override to decrypt a user-supplied file identifier and then pass the resolved path to Laravel's download response. Prior to version 1.8.224, the path resolution logic accepts any existing absolute path before applying the intended `storage/logs` restriction. As a result, an attacker who can access the App Logs route and forge a valid Laravel-encrypted `dl` parameter can download arbitrary server-local files readable by the PHP process, not just log files. Version 1.8.224 contains a fix.

Affected products

freescout
  • ==< 1.8.224

Matching in nixpkgs

Package maintainers

Package was introduced at 1.8.225 in nixpkgs
Permalink CVE-2026-53591
8.6 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): High (H)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): Low (L)
updated 6 days, 10 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed
FreeScout Vulnerable to Unauthenticated Conversation Thread Injection via HMAC Length Bypass in FetchEmails

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthenticated attacker can inject messages into any existing support conversation by sending a single email to the helpdesk's public address with a crafted `In-Reply-To` header. No credentials, tokens, or prior access are required. The injected message is rendered in the agent UI as a legitimate customer reply, the conversation is automatically reopened, and the `last_reply_from` field is set to the attacker's identity. Version 1.8.223 contains a fix.

Affected products

freescout
  • ==< 1.8.223

Matching in nixpkgs

Package maintainers

Package was introduced at 1.8.225 in nixpkgs
Permalink CVE-2026-53593
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 6 days, 10 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed
FreeScout Vulnerable to Authenticated Remote Code Execution via incomplete upload extension denylist (.pht) — bypass of CVE-2025-48471

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylist that neutralizes dangerous file uploads (`Helper::$restricted_extensions`) is incomplete: it does not cover the `.pht` extension. The authenticated upload endpoint `POST /uploads/upload` (`SecureController@upload`) stores files with their original extension into the web-accessible directory `storage/app/public/uploads/` (served at `/storage/uploads/`). On the standard Apache + `libapache2-mod-php` deployment, the default handler `<FilesMatch ".+\.ph(ar|p[3457]?|t|tml)$">` executes `.pht`, so **any authenticated agent can upload a `.pht` web shell and run arbitrary commands as the web-server user** (`www-data`). This is a direct bypass of the fix for CVE-2025-48471, which added `phtml`/`phar` but not `pht` (nor `phtm`, `phps`). Version 1.8.224 contains an updated fix.

Affected products

freescout
  • ==< 1.8.224

Matching in nixpkgs

Package maintainers

Package was introduced at 1.8.225 in nixpkgs
Permalink CVE-2026-53592
4.6 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 6 days, 10 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed
FreeScout vulnerable to prototype pollution in getQueryParam

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A Prototype Pollution condition in the `getQueryParam` function `/public/js/main.js` and was addressed in version 1.8.139 by blocking URL query keys matching the pattern `__proto__`. However, this mitigation is incomplete: it only filters top-level `__proto__` keys and fails to sanitize nested forms such as `b[__proto__][polluted]=PWNED`. As a result, an attacker-controlled URL query string can still write into `Object.prototype` on any page that loads `main.js`. Version 1.8.223 contains a updated fix.

Affected products

freescout
  • ==< 1.8.223

Matching in nixpkgs

Package maintainers

Package was introduced at 1.8.225 in nixpkgs
Permalink CVE-2026-45295
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 6 days, 10 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed
FreeScout Vulnerable to Unauthenticated Thread Read-Status Manipulation and Conversation Enumeration via Open Tracking Endpoint

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.219, the open tracking endpoint `GET /thread/read/{conversation_id}/{thread_id}` allows unauthenticated attackers to enumerate valid conversation and thread IDs, and modify thread state (`opened_at` timestamp) without any authentication. Version 1.8.219 patches the issue.

Affected products

freescout
  • ==< 1.8.219

Matching in nixpkgs

Package maintainers

Package was introduced at 1.8.225 in nixpkgs
Permalink CVE-2026-53595
9.4 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): Low (L)
updated 6 days, 10 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed
FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` (`OpenController@userSetupSave`) selects the target account solely by its `invite_hash` column, then overwrites that account's email and password and logs in as it. No authentication, cookie, or prior session is required. After a user activates, FreeScout sets `invite_hash` to the empty string. On MySQL and MariaDB, `VARCHAR` equality ignores trailing spaces, so a single URL-encoded space (`%20`) matches the stored empty string and selects the lowest-id activated user. The expiry guard decrypts `invite_sent_at` with the target's password hash, but `Helper::decrypt` returns its raw input unchanged when decryption fails. A plaintext numeric value such as `9999999999` therefore passes the time-to-live check without any secret. The result is that an anonymous attacker sets the email and password of the lowest-id activated FreeScout account (a support agent, or an administrator if one was added by invitation) and authenticates as that account. Version 1.8.224 contains a fix.

Affected products

freescout
  • ==< 1.8.224

Matching in nixpkgs

Package maintainers

Package was introduced at 1.8.225 in nixpkgs