Nixpkgs security tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
updated 5 months, 2 weeks ago by @jopejoe1 Activity log
  • Created suggestion
  • @jopejoe1 ignored
    28 packages
    • lunar
    • lunacy
    • lunarml
    • lunasvg
    • lunatic
    • lunarvim
    • lunatask
    • lunar-client
    • vulkan-tools-lunarg
    • python312Packages.luna-soc
    • python312Packages.luna-usb
    • python313Packages.luna-soc
    • python313Packages.luna-usb
    • python314Packages.luna-soc
    • python314Packages.luna-usb
    • gnomeExtensions.lunar-calendar
    • python312Packages.lunarcalendar
    • python313Packages.lunarcalendar
    • python314Packages.lunarcalendar
    • home-assistant-component-tests.lunatone
    • python312Packages.korean-lunar-calendar
    • python313Packages.korean-lunar-calendar
    • python314Packages.korean-lunar-calendar
    • gnomeExtensions.luna-moon-phase-indicator
    • python312Packages.lunatone-rest-api-client
    • python313Packages.lunatone-rest-api-client
    • python314Packages.lunatone-rest-api-client
    • tests.home-assistant-component-tests.lunatone
  • @jopejoe1 dismissed
Stored Cross-Site Scripting (XSS) in LUNA from Luna Imaging

Stored Cross-Site Scripting (XSS) vulnerability type in LUNA software v7.5.5.6. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by inyecting a malicious payload through the 'Edit Batch Name' function. THe payload is stored by the application and subsequently displayed without proper sanitization when other users access it. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.

Affected products

LUNA
  • ==7.5.5.6
Ignored packages (28)

pkgs.lunar

Defacto app for controlling monitors

pkgs.lunacy

Free design software that keeps your flow with AI tools and built-in graphics

  • nixos-unstable 11.6
    • nixpkgs-unstable 11.6
    • nixos-unstable-small 11.6

pkgs.lunarml

Standard ML compiler that produces Lua/JavaScript

pkgs.lunasvg

SVG rendering and manipulation library in C++

pkgs.lunatask

All-in-one encrypted todo list, notebook, habit and mood tracker, pomodoro timer, and journaling app

pkgs.lunar-client

Free Minecraft client with mods, cosmetics, and performance boost

pkgs.gnomeExtensions.luna-moon-phase-indicator

Luna is a simple GNOME Shell extension that displays the current moon phase directly in your top bar. With beautiful custom icons and real-time updates, Luna helps you stay attuned to lunar cycles throughout your day.

  • nixos-unstable 4
    • nixpkgs-unstable 4
    • nixos-unstable-small 4
Not present in nixpkgs
updated 5 months, 2 weeks ago by @jopejoe1 Activity log
  • Created suggestion
  • @jopejoe1 ignored
    21 packages
    • ssh-agents
    • lima-additional-guestagents
    • python312Packages.user-agents
    • python313Packages.user-agents
    • python314Packages.user-agents
    • python312Packages.pyuseragents
    • python313Packages.pyuseragents
    • python314Packages.pyuseragents
    • ocf-resource-agents
    • python312Packages.smolagents
    • python313Packages.smolagents
    • python314Packages.smolagents
    • python312Packages.openai-agents
    • python313Packages.openai-agents
    • python314Packages.openai-agents
    • python312Packages.bot-safe-agents
    • python313Packages.azure-ai-agents
    • python313Packages.bot-safe-agents
    • python314Packages.azure-ai-agents
    • python314Packages.bot-safe-agents
    • pkgsRocm.python3Packages.smolagents
  • @jopejoe1 dismissed
Insecure Direct Object Reference (IDOR) via Header-Based Email Routing

Summary An Insecure Direct Object Reference has been found to exist in `createHeaderBasedEmailResolver()` function within the Cloudflare Agents SDK. The issue occurs because the `Message-ID` and `References` headers are parsed to derive the target agentName and agentId without proper validation or origin checks, allowing an external attacker with control of these headers to route inbound mail to arbitrary Durable Object instances and namespaces . Root cause The `createHeaderBasedEmailResolver()` function lacks cryptographic verification or origin validation for the headers used in the routing logic, effectively allowing external input to dictate internal object routing. Impact Insecure Direct Object Reference (IDOR) in email routing lets an attacker steer inbound mail to arbitrary Agent instances via spoofed Message-ID. Mitigation: * PR: https://github.com/cloudflare/agents/blob/main/docs/email.md ] provides the necessary architectural context for coding agents to mitigate the issue by refactoring the resolver to enforce strict identity boundaries. * Agents-sdk users should upgrade to agents@0.3.7

Affected products

agents
  • =<0.3.6
Ignored packages (21)

pkgs.ssh-agents

Spawn and maintain multiple ssh-agents across terminals

Not present in nixpkgs, upstream repo https://github.com/cloudflare/agents
Permalink CVE-2025-52623
3.7 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 5 months, 2 weeks ago by @jopejoe1 Activity log
  • Created suggestion
  • @jopejoe1 ignored
    15 packages
    • python312Packages.aionut
    • python313Packages.aionut
    • python314Packages.aionut
    • python312Packages.aiontfy
    • python313Packages.aiontfy
    • python314Packages.aiontfy
    • python312Packages.aionotion
    • python313Packages.aionotion
    • python314Packages.aionotion
    • python312Packages.aionanoleaf
    • python313Packages.aionanoleaf
    • python314Packages.aionanoleaf
    • python312Packages.electrum-aionostr
    • python313Packages.electrum-aionostr
    • python314Packages.electrum-aionostr
  • @jopejoe1 dismissed
HCL AION is affected by an Autocomplete HTML Attribute Not Disabled for Password Field vulnerability

HCL AION is affected by an Autocomplete HTML Attribute Not Disabled for Password Field vulnerability. This can allow autocomplete on password fields may lead to unintended storage or disclosure of sensitive credentials, potentially increasing the risk of unauthorized access. This issue affects AION: 2.0.

Affected products

AION
  • ==2.0
Ignored packages (15)
Not present in nixpkgs
Permalink CVE-2025-52629
3.7 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 5 months, 2 weeks ago by @jopejoe1 Activity log
  • Created suggestion
  • @jopejoe1 ignored
    15 packages
    • python312Packages.aionut
    • python313Packages.aionut
    • python314Packages.aionut
    • python312Packages.aiontfy
    • python313Packages.aiontfy
    • python314Packages.aiontfy
    • python312Packages.aionotion
    • python313Packages.aionotion
    • python314Packages.aionotion
    • python312Packages.aionanoleaf
    • python313Packages.aionanoleaf
    • python314Packages.aionanoleaf
    • python312Packages.electrum-aionostr
    • python313Packages.electrum-aionostr
    • python314Packages.electrum-aionostr
  • @jopejoe1 dismissed
HCL AION is susceptible to Missing Content-Security-Policy

HCL AION is susceptible to Missing Content-Security-Policy.  An The absence of a CSP header may increase the risk of cross-site scripting and other content injection attacks by allowing unsafe scripts or resources to execute..This issue affects AION: 2.0.

Affected products

AION
  • ==2.0
Ignored packages (15)
Not present in nixpkgs
Permalink CVE-2025-52627
5.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Physical (P)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Physical (P)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 5 months, 2 weeks ago by @jopejoe1 Activity log
  • Created suggestion
  • @jopejoe1 ignored
    15 packages
    • python312Packages.aionut
    • python313Packages.aionut
    • python314Packages.aionut
    • python312Packages.aiontfy
    • python313Packages.aiontfy
    • python314Packages.aiontfy
    • python312Packages.aionotion
    • python313Packages.aionotion
    • python314Packages.aionotion
    • python312Packages.aionanoleaf
    • python313Packages.aionanoleaf
    • python314Packages.aionanoleaf
    • python312Packages.electrum-aionostr
    • python313Packages.electrum-aionostr
    • python314Packages.electrum-aionostr
  • @jopejoe1 dismissed
HCL AION is susceptible to Incorrect Permission Assignment for Critical Resource

Root File System Not Mounted as Read-Only configuration vulnerability. This can allow unintended modifications to critical system files, potentially increasing the risk of system compromise or unauthorized changes.This issue affects AION: 2.0.

Affected products

AION
  • ==2.0
Ignored packages (15)
Not present in nixpkgs
Permalink CVE-2025-15328
5.0 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 months, 2 weeks ago by @jopejoe1 Activity log
  • Created suggestion
  • @jopejoe1 ignored
    5 packages
    • haskellPackages.wai-enforce-https
    • python312Packages.lm-format-enforcer
    • python313Packages.lm-format-enforcer
    • python314Packages.lm-format-enforcer
    • vimPlugins.nvim-treesitter-parsers.enforce
  • @jopejoe1 dismissed
Tanium addressed an improper link resolution before file access vulnerability in Enforce.

Tanium addressed an improper link resolution before file access vulnerability in Enforce.

References

Affected products

Enforce
  • <2.8.544
  • <2.7.314
Ignored packages (5)
Not present in nixpkgs
Permalink CVE-2025-15289
3.1 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 months, 2 weeks ago by @jopejoe1 Activity log
  • Created suggestion
  • @jopejoe1 ignored
    20 packages
    • bash
    • interactsh
    • bashInteractive
    • gawkInteractive
    • coqPackages.ITree
    • bashInteractiveFHS
    • sqlite-interactive
    • texinfoInteractive
    • interactive-html-bom
    • kotlin-interactive-shell
    • perlPackages.IOInteractive
    • git-interactive-rebase-tool
    • perl538Packages.IOInteractive
    • perl540Packages.IOInteractive
    • perlPackages.IOInteractiveTiny
    • azure-cli-extensions.interactive
    • perl538Packages.IOInteractiveTiny
    • perl540Packages.IOInteractiveTiny
    • ocamlPackages.janeStreet.async_interactive
    • ocamlPackages_latest.janeStreet.async_interactive
  • @jopejoe1 dismissed
Tanium addressed an improper access controls vulnerability in Interact.

Tanium addressed an improper access controls vulnerability in Interact.

References

Affected products

Interact
  • <3.1.337
  • <3.2.185
  • <3.5.90
Ignored packages (20)

pkgs.interactsh

Out of bounds interaction gathering server and client library

pkgs.bashInteractive

GNU Bourne-Again Shell, the de facto standard shell on Linux (for interactive use)

pkgs.bashInteractiveFHS

GNU Bourne-Again Shell, the de facto standard shell on Linux (for interactive use)

pkgs.sqlite-interactive

Self-contained, serverless, zero-configuration, transactional SQL database engine

pkgs.interactive-html-bom

Interactive HTML BOM generation for KiCad, EasyEDA, Eagle, Fusion360 and Allegro PCB designer

Not present in nixpkgs
Permalink CVE-2025-15324
6.6 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 2 weeks ago by @jopejoe1 Activity log
  • Created suggestion
  • @jopejoe1 ignored package engage
  • @jopejoe1 dismissed
Tanium addressed a local privilege escalation vulnerability in Engage.

Tanium addressed a documentation issue in Engage.

References

Affected products

Engage
  • <1.3.37
  • <1.6.193
Ignored packages (1)

pkgs.engage

Task runner with DAG-based parallelism

Not present in nixpkgs
Permalink CVE-2020-37140
5.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 5 months, 2 weeks ago by @jopejoe1 Activity log
  • Created suggestion
  • @jopejoe1 ignored
    4 packages
    • everest
    • neverest
    • everest-bin
    • everest-mons
  • @jopejoe1 dismissed
Everest 5.50.2100 - 'Open File' Denial of Service

Everest, later referred to as AIDA64, 5.50.2100 contains a denial of service vulnerability that allows local attackers to crash the application by manipulating file open functionality. Attackers can generate a 450-byte buffer of repeated characters and paste it into the file open dialog to trigger an application crash.

Affected products

Everest
  • ==5.50.2100
Ignored packages (4)

pkgs.everest

Celeste mod loader (don't install; use celestegame instead)

  • nixos-unstable 6157
    • nixpkgs-unstable 6157
    • nixos-unstable-small 6157

pkgs.everest-bin

Celeste mod loader (don't install; use celestegame instead)

  • nixos-unstable 6157
    • nixpkgs-unstable 6157
    • nixos-unstable-small 6157

pkgs.everest-mons

Commandline Everest installer and mod manager for Celeste

Not present in nixpkgs also known as AIDA64
Permalink CVE-2025-15341
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 5 months, 2 weeks ago by @jopejoe1 Activity log
  • Created suggestion
  • @jopejoe1 ignored
    17 packages
    • gbenchmark
    • mqtt-benchmark
    • memtier-benchmark
    • rubyPackages.benchmark
    • ocamlPackages.benchmark
    • rubyPackages_3_1.benchmark
    • rubyPackages_3_2.benchmark
    • rubyPackages_3_3.benchmark
    • rubyPackages_3_4.benchmark
    • rubyPackages_4_0.benchmark
    • ocamlPackages_latest.benchmark
    • haskellPackages.benchmark-function
    • python312Packages.pytest-benchmark
    • python313Packages.pytest-benchmark
    • python314Packages.pytest-benchmark
    • haskellPackages.hashtable-benchmark
    • chickenPackages_5.chickenEggs.micro-benchmark
  • @jopejoe1 dismissed
Tanium addressed an incorrect default permissions vulnerability in Benchmark.

Tanium addressed an incorrect default permissions vulnerability in Benchmark.

References

Affected products

Benchmark
  • <2.12.82
  • <2.9.188
  • <2.7.98
Ignored packages (17)
Not present in nixpkgs