Nixpkgs Security Tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
updated 3 weeks, 4 days ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package moodle-dl
  • @LeSuisse dismissed
Moodle before 2.2.2 has a course information leak in gradebook …

Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export

References

Affected products

Moodle
  • ==2.2 to 2.2.1+
  • ==2.1 to 2.1.4+

Matching in nixpkgs

Ignored packages (1)

Package maintainers

Old issue current stable branch was never impacted.
updated 3 weeks, 4 days ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package moodle-dl
  • @LeSuisse dismissed
Moodle has a database activity export permission issue where the …

Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to

References

Affected products

Moodle
  • ==1.9.x
  • ==2.1.x
  • ==2.2.x
  • ==2.0.x

Matching in nixpkgs

Ignored packages (1)

Package maintainers

Old issue current stable branch was never impacted.
updated 3 weeks, 4 days ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package moodle-dl
  • @LeSuisse dismissed
Moodle before 2.2.2 has a password and web services issue …

Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.

References

Affected products

Moodle
  • ==2.0 to 2.0.7+
  • ==2.2 to 2.2.1+
  • ==2.1 to 2.1.4+

Matching in nixpkgs

Ignored packages (1)

Package maintainers

Old issue current stable branch was never impacted.
Permalink CVE-2020-36947
7.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
updated 3 weeks, 4 days ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse dismissed
LibreNMS 1.46 - MAC Accounting Graph Authenticated SQL Injection

LibreNMS 1.46 contains an authenticated SQL injection vulnerability in the MAC accounting graph endpoint that allows remote attackers to extract database information. Attackers can exploit the vulnerability by manipulating the 'sort' parameter with crafted SQL injection techniques to retrieve sensitive database contents through time-based blind SQL injection.

Affected products

LibreNMS
  • ==1.46

Matching in nixpkgs

Package maintainers

Old issue, current stable branch was never impacted
updated 3 weeks, 4 days ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    26 packages
    • haskellPackages.debuggable
    • haskellPackages.stringable
    • perlPackages.ModulePluggable
    • perl5Packages.ModulePluggable
    • perl538Packages.ModulePluggable
    • perl540Packages.ModulePluggable
    • perlPackages.ModulePluggableFast
    • perl5Packages.ModulePluggableFast
    • perlPackages.ModuleBuildPluggable
    • perl5Packages.ModuleBuildPluggable
    • perlPackages.MooseXTraitsPluggable
    • perl538Packages.ModulePluggableFast
    • perl540Packages.ModulePluggableFast
    • perl5Packages.MooseXTraitsPluggable
    • perl538Packages.ModuleBuildPluggable
    • perl540Packages.ModuleBuildPluggable
    • perl538Packages.MooseXTraitsPluggable
    • perl540Packages.MooseXTraitsPluggable
    • perlPackages.ModuleBuildPluggablePPPort
    • perl5Packages.ModuleBuildPluggablePPPort
    • perlPackages.ModuleBuildPluggableCPANfile
    • perl538Packages.ModuleBuildPluggablePPPort
    • perl540Packages.ModuleBuildPluggablePPPort
    • perl5Packages.ModuleBuildPluggableCPANfile
    • perl538Packages.ModuleBuildPluggableCPANfile
    • perl540Packages.ModuleBuildPluggableCPANfile
  • @LeSuisse dismissed
WordPress Gable theme <= 1.5 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Gable gable allows PHP Local File Inclusion.This issue affects Gable: from n/a through <= 1.5.

Affected products

gable
  • =<<= 1.5
Ignored packages (26)
WP theme not present in nixpkgs
updated 3 weeks, 4 days ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    20 packages
    • pj
    • pjsip
    • geoipjava
    • python312Packages.pjsua2
    • python313Packages.pjsua2
    • python314Packages.pjsua2
    • tests.fetchpatch2.simple
    • python312Packages.pypjlink2
    • python313Packages.pypjlink2
    • python314Packages.pypjlink2
    • tests.fetchFromGitHub.fetchTags
    • tests.fetchFromGitHub.simple-tag
    • python312Packages.jax-cuda12-pjrt
    • python313Packages.jax-cuda12-pjrt
    • python314Packages.jax-cuda12-pjrt
    • home-assistant-component-tests.pjlink
    • tests.fetchFromGitHub.submodule-simple
    • tests.testers.runCommand.dns-resolution
    • tests.fetchurl.flag-appending-curlOptsList
    • tests.home-assistant-component-tests.pjlink
  • @LeSuisse dismissed
WordPress PJ | Life & Business Coaching theme <= 3.0.0 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes PJ | Life & Business Coaching pj allows PHP Local File Inclusion.This issue affects PJ | Life & Business Coaching: from n/a through <= 3.0.0.

Affected products

pj
  • =<<= 3.0.0
Ignored packages (20)

pkgs.pj

Fast project directory finder that searches filesystems for git repositories

pkgs.pjsip

Multimedia communication library written in C, implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE

pkgs.python314Packages.pjsua2

Multimedia communication library written in C, implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE

Not present in nixpkgs
updated 3 weeks, 4 days ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    6 packages
    • prometheus-opnsense-exporter
    • python312Packages.pyopnsense
    • python313Packages.pyopnsense
    • python314Packages.pyopnsense
    • home-assistant-component-tests.opnsense
    • tests.home-assistant-component-tests.opnsense
  • @LeSuisse dismissed
Deciso OPNsense diag_backup.php filename Command Injection Remote Code Execution Vulnerability

Deciso OPNsense diag_backup.php filename Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Deciso OPNsense. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of backup configuration files. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-28131.

References

Affected products

OPNsense
  • ==25.7
Ignored packages (6)
Not present in nixpkgs
Permalink CVE-2026-22372
8.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): HIGH
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
updated 3 weeks, 4 days ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package visidata
  • @LeSuisse dismissed
WordPress Isida theme <= 1.4.2 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Isida isida allows PHP Local File Inclusion.This issue affects Isida: from n/a through <= 1.4.2.

Affected products

isida
  • =<<= 1.4.2
Ignored packages (1)

pkgs.visidata

Interactive terminal multitool for tabular data

WP theme not present in nixpkgs
Permalink CVE-2026-2850
6.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
updated 3 weeks, 4 days ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package warehouse
  • @LeSuisse dismissed
yeqifu warehouse Customer Endpoint CustomerController.java deleteCustomer access control

A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function addCustomer/updateCustomer/deleteCustomer of the file dataset\repos\warehouse\src\main\java\com\yeqifu\bus\controller\CustomerController.java of the component Customer Endpoint. Performing a manipulation results in improper access controls. Remote exploitation of the attack is possible. The exploit has been made public and could be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

warehouse
  • ==aaf29962ba407d22d991781de28796ee7b4670e4
Ignored packages (1)
Not present in nixpkgs
Permalink CVE-2026-2851
6.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
updated 3 weeks, 4 days ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package warehouse
  • @LeSuisse dismissed
yeqifu warehouse Inport Endpoint InportController.java deleteInport access control

A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This vulnerability affects the function addInport/updateInport/deleteInport of the file dataset\repos\warehouse\src\main\java\com\yeqifu\bus\controller\InportController.java of the component Inport Endpoint. Executing a manipulation can lead to improper access controls. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

warehouse
  • ==aaf29962ba407d22d991781de28796ee7b4670e4
Ignored packages (1)
Not present in nixpkgs