Nixpkgs security tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Permalink CVE-2026-24845
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package malcontent-ui
  • @LeSuisse accepted
  • @LeSuisse ignored package malcontent
  • @LeSuisse dismissed
malcontent's OCI image scanning could expose registry credentials

malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 0.10.0 and prior to version 1.20.3, malcontent could be made to expose Docker registry credentials if it scanned a specially crafted OCI image reference. malcontent uses google/go-containerregistry for OCI image pulls, which by default uses the Docker credential keychain. A malicious registry could return a `WWW-Authenticate` header redirecting token authentication to an attacker-controlled endpoint, causing credentials to be sent to that endpoint. Version 1.20.3 fixes the issue by defaulting to anonymous auth for OCI pulls.

Affected products

malcontent
  • ==>= 0.10.0, < 1.20.3
Ignored packages (2)
Chainguard malcontent is not present in nixpkgs.
Permalink CVE-2026-24846
5.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 5 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    2 packages
    • malcontent-ui
    • malcontent
  • @LeSuisse dismissed
malcontent's archive extraction could write outside extraction directory

malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 1.8.0 and prior to version 1.20.3, malcontent could be made to create symlinks outside the intended extraction directory when scanning a specially crafted tar or deb archive. The `handleSymlink` function received arguments in the wrong order, causing the symlink target to be used as the symlink location. Additionally, symlink targets were not validated to ensure they resolved within the extraction directory. Version 1.20.3 introduces fixes that swap handleSymlink arguments, validate symlink location, and validate symlink targets that resolve within an extraction directory.

Affected products

malcontent
  • ==>= 1.8.0, < 1.20.3
Ignored packages (2)
Chainguard malcontent is not present in nixpkgs.
Permalink CVE-2026-24854
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    4 packages
    • ocrmypdf
    • python312Packages.ocrmypdf
    • python313Packages.ocrmypdf
    • wordpressPackages.plugins.civicrm
  • @LeSuisse dismissed
Church CRM has SQL injection in PaddleNumEditor.php

ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in endpoint `/PaddleNumEditor.php` in ChurchCRM prior to version 6.7.2. Any authenticated user, including one with zero assigned permissions, can exploit SQL injection through the `PerID` parameter. Version 6.7.2 contains a patch for the issue.

Affected products

CRM
  • ==< 6.7.2
Ignored packages (4)

pkgs.ocrmypdf

Adds an OCR text layer to scanned PDF files, allowing them to be searched

Not present in nixpkgs
Permalink CVE-2020-36966
6.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 5 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed
Dolibarr 11.0.3 - 'ldap.php' - Persistent Cross-Site Scripting

Dolibarr 11.0.3 contains a persistent cross-site scripting vulnerability in LDAP synchronization settings that allows attackers to inject malicious scripts through multiple parameters. Attackers can exploit the host, slave, and port parameters in /dolibarr/admin/ldap.php to execute arbitrary JavaScript and potentially steal user cookie information.

Affected products

Dolibarr
  • =<11.0.3

Matching in nixpkgs

pkgs.dolibarr

Enterprise resource planning (ERP) and customer relationship manager (CRM) server

Package maintainers

Current stable was never impacted
Permalink CVE-2025-47363
6.8 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Physical (P)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Physical (P)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package snapdragon-profiler
  • @LeSuisse dismissed
Integer Overflow or Wraparound in Automotive

Memory corruption when calculating oversized partition sizes without proper checks.

Affected products

Snapdragon
  • ==QAMSRV1H
  • ==SA8195P
  • ==SA8775P
  • ==QAM8650P
  • ==QCA6595
  • ==QCA6688AQ
  • ==QAM8775P
  • ==SA6155P
  • ==SA8620P
  • ==QAM8255P
  • ==SRV1H
  • ==QCA6574AU
  • ==SA6145P
  • ==QCA6595AU
  • ==SA8650P
  • ==SRV1L
  • ==QAM8295P
  • ==SA7775P
  • ==SA8255P
  • ==QCA8695AU
  • ==SA8155P
  • ==QCA6696
  • ==SRV1M
  • ==SA8145P
  • ==SA8540P
  • ==SA8770P
  • ==SA9000P
  • ==QAMSRV1M
  • ==SA8295P
  • ==QCA6797AQ
  • ==QCA6698AQ
  • ==SA6150P
  • ==SA7255P
  • ==QAM8620P
  • ==SA8150P
Ignored packages (1)
Not present in nixpkgs
Permalink CVE-2022-50897
6.2 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @jopejoe1 ignored package termpdfpy
  • @LeSuisse dismissed
mPDF 7.0 - Local File Inclusion

mPDF 7.0 contains a local file inclusion vulnerability that allows attackers to read arbitrary system files by manipulating annotation file parameters. Attackers can generate URL-encoded or base64 payloads to include local files through crafted annotation content with file path specifications.

Affected products

mPDF
  • ==7.0
Ignored packages (1)
Not present in nixpkgs
Permalink CVE-2025-47366
7.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 5 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @jopejoe1 ignored package snapdragon-profiler
  • @LeSuisse dismissed
Exposed Dangerous Method or Function in HLOS

Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.

Affected products

Snapdragon
  • ==QCA8081
  • ==SA8195P
  • ==QCS5430
  • ==QCN6224
  • ==WSA8845
  • ==Qualcomm Video Collaboration VC5 Platform
  • ==WCN6650
  • ==QRU1052
  • ==SM8650Q
  • ==SC8380XP
  • ==Snapdragon 480 5G Mobile Platform
  • ==WCN6755
  • ==QRU1062
  • ==SM8750P
  • ==QMP1000
  • ==Snapdragon X32 5G Modem-RF System
  • ==SA4155P
  • ==Snapdragon 662 Mobile Platform
  • ==SA8255P
  • ==QCA8695AU
  • ==QFW7124
  • ==Snapdragon AR2 Gen 1 Platform
  • ==QCA6174A
  • ==QRB5165M
  • ==SD 8 Gen1 5G
  • ==Snapdragon 685 4G Mobile Platform (SM6225-AD)
  • ==SA8540P
  • ==SM7675
  • ==SA9000P
  • ==SM8750
  • ==Snapdragon 4 Gen 2 Mobile Platform
  • ==WCD9395
  • ==QCA6584AU
  • ==SM7635
  • ==SA7255P
  • ==QCA6698AQ
  • ==SA6150P
  • ==QCN6274
  • ==QAM8620P
  • ==SM8735
  • ==QCN9011
  • ==QCN9012
  • ==SA8775P
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==Snapdragon X72 5G Modem-RF System
  • ==QAM8650P
  • ==SXR2350P
  • ==QCA6678AQ
  • ==SW5100
  • ==Flight RB5 5G Platform
  • ==SSG2115P
  • ==Snapdragon AR1 Gen 1 Platform "Luna1"
  • ==Snapdragon Auto 5G Modem-RF Gen 2
  • ==SA8620P
  • ==SSG2125P
  • ==SM6225P
  • ==Snapdragon 7 Gen 1 Mobile Platform
  • ==QAM8255P
  • ==QFW7114
  • ==SM6650
  • ==QRB5165N
  • ==Snapdragon W5+ Gen 1 Wearable Platform
  • ==QDX1010
  • ==FastConnect 7800
  • ==WCN7881
  • ==SA8155P
  • ==SM8475P
  • ==AR8035
  • ==QCS7230
  • ==QCA6696
  • ==SRV1M
  • ==SA8770P
  • ==WSA8815
  • ==WCD9380
  • ==QDX1011
  • ==QRU1032
  • ==SA8295P
  • ==QCA6797AQ
  • ==WSA8845H
  • ==WCN7860
  • ==Snapdragon 6 Gen 1 Mobile Platform
  • ==WSA8835
  • ==SXR2250P
  • ==WCN3988
  • ==SM8635P
  • ==QCA6595
  • ==WCN7861
  • ==QAM8775P
  • ==QCM6490
  • ==SA6155P
  • ==SW5100P
  • ==QCA6391
  • ==Snapdragon 460 Mobile Platform
  • ==QCS4490
  • ==SM6475
  • ==Snapdragon 695 5G Mobile Platform
  • ==SRV1H
  • ==SM6650P
  • ==Snapdragon 480+ 5G Mobile Platform (SM4350-AC)
  • ==QDU1010
  • ==WCD9370
  • ==Snapdragon AR1 Gen 1 Platform
  • ==SA6145P
  • ==QCA6574
  • ==QCA6595AU
  • ==QAM8295P
  • ==Snapdragon 680 4G Mobile Platform
  • ==WSA8832
  • ==SM4635
  • ==FastConnect 6900
  • ==WCN7880
  • ==SXR2230P
  • ==FastConnect 6200
  • ==QCM5430
  • ==QCS6490
  • ==WCN3950
  • ==QCA8337
  • ==QEP8111
  • ==SA4150P
  • ==QAMSRV1M
  • ==Robotics RB5 Platform
  • ==SXR2330P
  • ==QAMSRV1H
  • ==QCS615
  • ==SG4150P
  • ==WCN3910
  • ==WCN6740
  • ==WCD9385
  • ==QCA6688AQ
  • ==WSA8830
  • ==QCA6574A
  • ==SM8635
  • ==WCD9390
  • ==SXR1230P
  • ==WCD9375
  • ==SM7435
  • ==WCD9378
  • ==QCS9100
  • ==FastConnect 6700
  • ==QCA6574AU
  • ==Snapdragon 7+ Gen 2 Mobile Platform
  • ==SRV1L
  • ==SA8650P
  • ==SA7775P
  • ==Snapdragon 8+ Gen 1 Mobile Platform
  • ==Snapdragon 8 Gen 1 Mobile Platform
  • ==Snapdragon X75 5G Modem-RF System
  • ==WSA8840
  • ==SM7675P
  • ==SA8145P
  • ==WSA8810
  • ==SM7635P
  • ==WCD9340
  • ==WCN7750
  • ==QCM4490
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==SA8150P
  • ==Snapdragon X35 5G Modem-RF System
  • ==QCC710
  • ==Snapdragon 4 Gen 1 Mobile Platform
Ignored packages (1)
Not present in nixpkgs
Permalink CVE-2025-47364
6.8 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Physical (P)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Physical (P)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @jopejoe1 ignored package snapdragon-profiler
  • @LeSuisse dismissed
Integer Overflow or Wraparound in Automotive

Memory corruption while calculating offset from partition start point.

Affected products

Snapdragon
  • ==QAMSRV1H
  • ==SA8195P
  • ==SA8775P
  • ==QAM8650P
  • ==QCA6595
  • ==QCA6688AQ
  • ==QAM8775P
  • ==SA6155P
  • ==SA8620P
  • ==QAM8255P
  • ==SRV1H
  • ==QCA6574AU
  • ==SA6145P
  • ==QCA6595AU
  • ==SA8650P
  • ==SRV1L
  • ==QAM8295P
  • ==SA7775P
  • ==SA8255P
  • ==QCA8695AU
  • ==SA8155P
  • ==SRV1M
  • ==QCA6696
  • ==SA8145P
  • ==SA8540P
  • ==SA8770P
  • ==SA9000P
  • ==QAMSRV1M
  • ==SA8295P
  • ==QCA6797AQ
  • ==QCA6698AQ
  • ==SA6150P
  • ==SA7255P
  • ==QAM8620P
  • ==SA8150P
Ignored packages (1)
Not present in nixpkgs
Permalink CVE-2025-47398
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @jopejoe1 ignored package snapdragon-profiler
  • @LeSuisse dismissed
Use After Free in Graphics

Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers.

Affected products

Snapdragon
  • ==SA8195P
  • ==WSA8845
  • ==Qualcomm Video Collaboration VC5 Platform
  • ==WCN6650
  • ==SM8650Q
  • ==Snapdragon 480 5G Mobile Platform
  • ==SM8550P
  • ==WCN6755
  • ==SM8750P
  • ==LeMansAU
  • ==QMP1000
  • ==WCD9371
  • ==Snapdragon 662 Mobile Platform
  • ==SA8255P
  • ==QCA8695AU
  • ==SM7550
  • ==SD 8 Gen1 5G
  • ==SM7675
  • ==Snapdragon 6 Gen 3 Mobile Platform
  • ==SA9000P
  • ==Snapdragon 6 Gen 4 Mobile Platform
  • ==QCS4290
  • ==Snapdragon 4 Gen 2 Mobile Platform
  • ==WCD9395
  • ==IQ9 Series Platform
  • ==QCA6698AQ
  • ==SA7255P
  • ==Netrani
  • ==QCN9011
  • ==QCN9012
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==CSRA6640
  • ==SXR2350P
  • ==QCA6678AQ
  • ==SW5100
  • ==Flight RB5 5G Platform
  • ==SSG2115P
  • ==SSG2125P
  • ==Monaco_IOT
  • ==SA8620P
  • ==SM6225P
  • ==Snapdragon 7 Gen 1 Mobile Platform
  • ==QAM8255P
  • ==IQ8 Series Platform
  • ==Snapdragon 8 Elite
  • ==SM7550P
  • ==QRB5165N
  • ==Snapdragon W5+ Gen 1 Wearable Platform
  • ==FastConnect 7800
  • ==QCM2290
  • ==WCN7881
  • ==G1 Gen 1
  • ==Qualcomm Video Collaboration VC1 Platform
  • ==SA8155P
  • ==SM8475P
  • ==Smart Audio 400 Platform
  • ==QCA6696
  • ==QCA2066
  • ==SRV1M
  • ==SA8770P
  • ==WSA8815
  • ==WCD9380
  • ==QCM6125
  • ==SA8295P
  • ==Orne
  • ==QCA6797AQ
  • ==Robotics RB2 Platform
  • ==WSA8845H
  • ==Snapdragon 8 Gen 2 Mobile Platform
  • ==WCD9335
  • ==WCN7860
  • ==Snapdragon 6 Gen 1 Mobile Platform
  • ==LeMans_AU_LGIT
  • ==WSA8835
  • ==WCN3980
  • ==SXR2250P
  • ==WCN3988
  • ==SM8635P
  • ==QCA6595
  • ==WCN7861
  • ==Palawan25
  • ==SA6155P
  • ==QCM6490
  • ==SW5100P
  • ==QCA6391
  • ==Snapdragon 460 Mobile Platform
  • ==Milos
  • ==QCS4490
  • ==Snapdragon 480+ 5G Mobile Platform
  • ==Snapdragon 695 5G Mobile Platform
  • ==Snapdragon 685 4G Mobile Platform
  • ==SRV1H
  • ==SM6650P
  • ==WCD9370
  • ==Snapdragon AR1 Gen 1 Platform
  • ==Snapdragon 7s Gen 3 Mobile Platform
  • ==QCA6574
  • ==QCA6595AU
  • ==QCM4325
  • ==QAM8295P
  • ==Snapdragon 680 4G Mobile Platform
  • ==CSRA6620
  • ==WSA8832
  • ==FastConnect 6900
  • ==QCA6698AU
  • ==WCN7880
  • ==QCS2290
  • ==SXR2230P
  • ==FastConnect 6200
  • ==QCM5430
  • ==WCN3950
  • ==SAR2130P
  • ==Snapdragon 8+ Gen 2 Mobile Platform
  • ==QAMSRV1M
  • ==QCS410
  • ==Robotics RB5 Platform
  • ==QCS8550
  • ==SXR2330P
  • ==QAMSRV1H
  • ==WCN3910
  • ==WCD9385
  • ==QCA6688AQ
  • ==IQ6 Series Platform
  • ==WSA8830
  • ==QCA6574A
  • ==SD662
  • ==SM8635
  • ==WCD9390
  • ==SXR1230P
  • ==WCD9375
  • ==SM7435
  • ==WCD9378
  • ==FastConnect 6700
  • ==QCA6574AU
  • ==Snapdragon 7+ Gen 2 Mobile Platform
  • ==SA7775P
  • ==SDA660
  • ==WCN3990
  • ==Snapdragon 8+ Gen 1 Mobile Platform
  • ==Snapdragon 8 Gen 1 Mobile Platform
  • ==WSA8840
  • ==G2 Gen 1
  • ==WCD9341
  • ==SM7675P
  • ==Snapdragon 660 Mobile Platform
  • ==WSA8810
  • ==SM7635P
  • ==QCM4490
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==AR8031
  • ==Snapdragon 4 Gen 1 Mobile Platform
Ignored packages (1)
Not present in nixpkgs
Permalink CVE-2025-6591
4.7 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed
HTML injection in API action=feedcontributions output from i18n message

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/api/ApiFeedContributions.Php. This issue affects MediaWiki: from * before 1.39.13, 1.42.7 1.43.2, 1.44.0.

Affected products

MediaWiki
  • <1.39.13, 1.42.7 1.43.2, 1.44.0

Matching in nixpkgs

pkgs.mediawiki

Collaborative editing software that runs Wikipedia

Package maintainers

Current stable was never impacted.

https://github.com/NixOS/nixpkgs/commit/ebc9ceccc71196b1b32b198377b362dffa3ea30e