Nixpkgs security tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package moodle-dl
  • @LeSuisse dismissed
Moodle before 2.2.2: Overview report allows users to see hidden …

Moodle before 2.2.2: Overview report allows users to see hidden courses

Affected products

Moodle
  • ==2.1 to 2.1.4+
  • ==2.2 to 2.2.1+

Matching in nixpkgs

pkgs.moodle

Free and open-source learning management system (LMS) written in PHP

Ignored packages (1)

pkgs.moodle-dl

Moodle downloader that downloads course content fast from Moodle

Old issue current stable branch was never impacted.
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package moodle-dl
  • @LeSuisse dismissed
Moodle before 2.2.2 has a course information leak in gradebook …

Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export

Affected products

Moodle
  • ==2.1 to 2.1.4+
  • ==2.2 to 2.2.1+

Matching in nixpkgs

pkgs.moodle

Free and open-source learning management system (LMS) written in PHP

Ignored packages (1)

pkgs.moodle-dl

Moodle downloader that downloads course content fast from Moodle

Old issue current stable branch was never impacted.
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package moodle-dl
  • @LeSuisse dismissed
Moodle has a database activity export permission issue where the …

Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to

Affected products

Moodle
  • ==1.9.x
  • ==2.1.x
  • ==2.0.x
  • ==2.2.x

Matching in nixpkgs

pkgs.moodle

Free and open-source learning management system (LMS) written in PHP

Ignored packages (1)

pkgs.moodle-dl

Moodle downloader that downloads course content fast from Moodle

Old issue current stable branch was never impacted.
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package moodle-dl
  • @LeSuisse dismissed
Moodle before 2.2.2 has a password and web services issue …

Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.

Affected products

Moodle
  • ==2.0 to 2.0.7+
  • ==2.1 to 2.1.4+
  • ==2.2 to 2.2.1+

Matching in nixpkgs

pkgs.moodle

Free and open-source learning management system (LMS) written in PHP

Ignored packages (1)

pkgs.moodle-dl

Moodle downloader that downloads course content fast from Moodle

Old issue current stable branch was never impacted.
Permalink CVE-2020-36947
7.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed
LibreNMS 1.46 - MAC Accounting Graph Authenticated SQL Injection

LibreNMS 1.46 contains an authenticated SQL injection vulnerability in the MAC accounting graph endpoint that allows remote attackers to extract database information. Attackers can exploit the vulnerability by manipulating the 'sort' parameter with crafted SQL injection techniques to retrieve sensitive database contents through time-based blind SQL injection.

Affected products

LibreNMS
  • ==1.46

Matching in nixpkgs

pkgs.librenms

Auto-discovering PHP/MySQL/SNMP based network monitoring

Package maintainers

Old issue, current stable branch was never impacted
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    26 packages
    • haskellPackages.debuggable
    • haskellPackages.stringable
    • perlPackages.ModulePluggable
    • perl5Packages.ModulePluggable
    • perl538Packages.ModulePluggable
    • perl540Packages.ModulePluggable
    • perlPackages.ModulePluggableFast
    • perl5Packages.ModulePluggableFast
    • perlPackages.ModuleBuildPluggable
    • perl5Packages.ModuleBuildPluggable
    • perlPackages.MooseXTraitsPluggable
    • perl538Packages.ModulePluggableFast
    • perl540Packages.ModulePluggableFast
    • perl5Packages.MooseXTraitsPluggable
    • perl538Packages.ModuleBuildPluggable
    • perl540Packages.ModuleBuildPluggable
    • perl538Packages.MooseXTraitsPluggable
    • perl540Packages.MooseXTraitsPluggable
    • perlPackages.ModuleBuildPluggablePPPort
    • perl5Packages.ModuleBuildPluggablePPPort
    • perlPackages.ModuleBuildPluggableCPANfile
    • perl538Packages.ModuleBuildPluggablePPPort
    • perl540Packages.ModuleBuildPluggablePPPort
    • perl5Packages.ModuleBuildPluggableCPANfile
    • perl538Packages.ModuleBuildPluggableCPANfile
    • perl540Packages.ModuleBuildPluggableCPANfile
  • @LeSuisse dismissed
WordPress Gable theme <= 1.5 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Gable gable allows PHP Local File Inclusion.This issue affects Gable: from n/a through <= 1.5.

Affected products

gable
  • =<<= 1.5
Ignored packages (26)
WP theme not present in nixpkgs
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    20 packages
    • pj
    • pjsip
    • geoipjava
    • python312Packages.pjsua2
    • python313Packages.pjsua2
    • python314Packages.pjsua2
    • tests.fetchpatch2.simple
    • python312Packages.pypjlink2
    • python313Packages.pypjlink2
    • python314Packages.pypjlink2
    • tests.fetchFromGitHub.fetchTags
    • tests.fetchFromGitHub.simple-tag
    • python312Packages.jax-cuda12-pjrt
    • python313Packages.jax-cuda12-pjrt
    • python314Packages.jax-cuda12-pjrt
    • home-assistant-component-tests.pjlink
    • tests.fetchFromGitHub.submodule-simple
    • tests.testers.runCommand.dns-resolution
    • tests.fetchurl.flag-appending-curlOptsList
    • tests.home-assistant-component-tests.pjlink
  • @LeSuisse dismissed
WordPress PJ | Life & Business Coaching theme <= 3.0.0 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes PJ | Life & Business Coaching pj allows PHP Local File Inclusion.This issue affects PJ | Life & Business Coaching: from n/a through <= 3.0.0.

Affected products

pj
  • =<<= 3.0.0
Ignored packages (20)

pkgs.pj

Fast project directory finder that searches filesystems for git repositories

pkgs.pjsip

Multimedia communication library written in C, implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE

  • nixos-unstable 2.16
    • nixpkgs-unstable 2.16
    • nixos-unstable-small 2.16

pkgs.python313Packages.pjsua2

Multimedia communication library written in C, implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE

  • nixos-unstable 2.16
    • nixpkgs-unstable 2.16
    • nixos-unstable-small 2.16

pkgs.python314Packages.pjsua2

Multimedia communication library written in C, implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE

  • nixos-unstable 2.16
    • nixpkgs-unstable 2.16
    • nixos-unstable-small 2.16
Not present in nixpkgs
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    6 packages
    • prometheus-opnsense-exporter
    • python312Packages.pyopnsense
    • python313Packages.pyopnsense
    • python314Packages.pyopnsense
    • home-assistant-component-tests.opnsense
    • tests.home-assistant-component-tests.opnsense
  • @LeSuisse dismissed
Deciso OPNsense diag_backup.php filename Command Injection Remote Code Execution Vulnerability

Deciso OPNsense diag_backup.php filename Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Deciso OPNsense. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of backup configuration files. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-28131.

References

Affected products

OPNsense
  • ==25.7
Ignored packages (6)
Not present in nixpkgs
Permalink CVE-2026-22372
8.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package visidata
  • @LeSuisse dismissed
WordPress Isida theme <= 1.4.2 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Isida isida allows PHP Local File Inclusion.This issue affects Isida: from n/a through <= 1.4.2.

Affected products

isida
  • =<<= 1.4.2
Ignored packages (1)

pkgs.visidata

Interactive terminal multitool for tabular data

  • nixos-unstable 3.3
    • nixpkgs-unstable 3.3
    • nixos-unstable-small 3.3
WP theme not present in nixpkgs
Permalink CVE-2026-2850
6.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 5 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package warehouse
  • @LeSuisse dismissed
yeqifu warehouse Customer Endpoint CustomerController.java deleteCustomer access control

A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function addCustomer/updateCustomer/deleteCustomer of the file dataset\repos\warehouse\src\main\java\com\yeqifu\bus\controller\CustomerController.java of the component Customer Endpoint. Performing a manipulation results in improper access controls. Remote exploitation of the attack is possible. The exploit has been made public and could be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

warehouse
  • ==aaf29962ba407d22d991781de28796ee7b4670e4
Ignored packages (1)
Not present in nixpkgs