Nixpkgs Security Tracker

Login with GitHub

Automatically generated suggestions

to remove a suggestion from the queue.

created 20 hours ago
Craft Commerce has Stored XSS in Product Type Name

Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, there is a Stored XSS via Product Type names. The name is not sanitized when displayed in user permissions settings. The vulnerable input (source) is in Commerce (Product Type settings), but the sink is in CMS user permissions settings. This issue has been patched in versions 4.10.1 and 5.5.2.

Affected products

commerce
  • ==>= 5.0.0, < 5.5.2
  • ==>= 4.0.0-RC1, < 4.10.1

Matching in nixpkgs

pkgs.python312Packages.azure-mgmt-commerce

This is the Microsoft Azure Commerce Management Client Library

pkgs.python313Packages.azure-mgmt-commerce

This is the Microsoft Azure Commerce Management Client Library

pkgs.python314Packages.azure-mgmt-commerce

This is the Microsoft Azure Commerce Management Client Library

pkgs.python313Packages.mypy-boto3-marketplacecommerceanalytics

Type annotations for boto3 marketplacecommerceanalytics

pkgs.python312Packages.types-aiobotocore-marketplacecommerceanalytics

Type annotations for aiobotocore marketplacecommerceanalytics

pkgs.python313Packages.types-aiobotocore-marketplacecommerceanalytics

Type annotations for aiobotocore marketplacecommerceanalytics

Package maintainers

created 20 hours ago
Watchlist group mode reveals authors of edits with hidden authorship

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/RecentChanges/EnhancedChangesList.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.

Affected products

MediaWiki
  • <1.39.14, 1.43.4, 1.44.1

Matching in nixpkgs

Package maintainers

created 20 hours ago
Moodle: moodle: formula injection allows arbitrary formula execution via unescaped data export

A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker could exploit this by providing malicious data that, when exported and opened in a spreadsheet, allows arbitrary formulas to execute. This can lead to compromised data integrity and unintended operations within the spreadsheet.

Affected products

moodle
  • <4.5.8
  • <5.1.1
  • <4.4.12
  • <4.1.22
  • <5.0.4

Matching in nixpkgs

pkgs.moodle

Free and open-source learning management system (LMS) written in PHP

Package maintainers

created 20 hours ago
Moodle: moodle: privilege escalation via incomplete role checks in badge awarding

A flaw was found in Moodle. An authorization logic flaw, specifically due to incomplete role checks during the badge awarding process, allowed badges to be granted without proper verification. This could enable unauthorized users to obtain badges they are not entitled to, potentially leading to privilege escalation or unauthorized access to certain features.

Affected products

moodle
  • <4.5.8
  • <5.1.1
  • <4.4.12
  • <4.1.22
  • <5.0.4

Matching in nixpkgs

pkgs.moodle

Free and open-source learning management system (LMS) written in PHP

Package maintainers

created 20 hours ago
mw.message(…).parse() doesn't output safe HTML, but it's being used as if it does

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.JqueryMsg/mediawiki.JqueryMsg.Js. This issue affects MediaWiki: from * before 1.39.16, 1.43.6, 1.44.3, 1.45.1.

Affected products

MediaWiki
  • <1.39.16, 1.43.6, 1.44.3, 1.45.1

Matching in nixpkgs

Package maintainers

created 20 hours ago
HCL AION is affected by an Autocomplete HTML Attribute Not Disabled for Password Field vulnerability

HCL AION is affected by an Autocomplete HTML Attribute Not Disabled for Password Field vulnerability. This can allow autocomplete on password fields may lead to unintended storage or disclosure of sensitive credentials, potentially increasing the risk of unauthorized access. This issue affects AION: 2.0.

Affected products

AION
  • ==2.0

Matching in nixpkgs

pkgs.python312Packages.aionut

Asyncio Network UPS Tools

pkgs.python314Packages.aionut

Asyncio Network UPS Tools

pkgs.python312Packages.aiontfy

Async ntfy client library

pkgs.python314Packages.aiontfy

Async ntfy client library

pkgs.python312Packages.aionanoleaf

Python wrapper for the Nanoleaf API

pkgs.python314Packages.aionanoleaf

Python wrapper for the Nanoleaf API

pkgs.python312Packages.electrum-aionostr

Asyncio nostr client

pkgs.python313Packages.electrum-aionostr

Asyncio nostr client

pkgs.python314Packages.electrum-aionostr

Asyncio nostr client

Package maintainers

created 20 hours ago
Craft CMS has Stored XSS in Tax Rates Name Leading to Potential Privilege Escalation

Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator's browser. This occurs because the Tax Rates 'Name' field in the Store Management section is not properly sanitized before being displayed in the admin panel. This issue has been patched in versions 4.10.1 and 5.5.2.

Affected products

commerce
  • ==>= 5.0.0, < 5.5.2
  • ==>= 4.0.0-RC1, < 4.10.1

Matching in nixpkgs

pkgs.python312Packages.azure-mgmt-commerce

This is the Microsoft Azure Commerce Management Client Library

pkgs.python313Packages.azure-mgmt-commerce

This is the Microsoft Azure Commerce Management Client Library

pkgs.python314Packages.azure-mgmt-commerce

This is the Microsoft Azure Commerce Management Client Library

pkgs.python313Packages.mypy-boto3-marketplacecommerceanalytics

Type annotations for boto3 marketplacecommerceanalytics

pkgs.python312Packages.types-aiobotocore-marketplacecommerceanalytics

Type annotations for aiobotocore marketplacecommerceanalytics

pkgs.python313Packages.types-aiobotocore-marketplacecommerceanalytics

Type annotations for aiobotocore marketplacecommerceanalytics

Package maintainers

created 20 hours ago
Stored Cross-Site Scripting (XSS) in LUNA from Luna Imaging

Stored Cross-Site Scripting (XSS) vulnerability type in LUNA software v7.5.5.6. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by inyecting a malicious payload through the 'Edit Batch Name' function. THe payload is stored by the application and subsequently displayed without proper sanitization when other users access it. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.

Affected products

LUNA
  • ==7.5.5.6

Matching in nixpkgs

pkgs.lunar

Defacto app for controlling monitors

pkgs.lunacy

Free design software that keeps your flow with AI tools and built-in graphics

pkgs.lunatask

All-in-one encrypted todo list, notebook, habit and mood tracker, pomodoro timer, and journaling app

pkgs.python312Packages.luna-soc

Amaranth HDL library for building USB-capable SoC designs

pkgs.python312Packages.luna-usb

Amaranth HDL framework for monitoring, hacking, and developing USB devices

pkgs.python313Packages.luna-soc

Amaranth HDL library for building USB-capable SoC designs

pkgs.python313Packages.luna-usb

Amaranth HDL framework for monitoring, hacking, and developing USB devices

pkgs.python314Packages.luna-soc

Amaranth HDL library for building USB-capable SoC designs

pkgs.python314Packages.luna-usb

Amaranth HDL framework for monitoring, hacking, and developing USB devices

pkgs.gnomeExtensions.lunar-calendar

Display Chinese Lunar Calendar in panel

  • nixos-unstable 54
    • nixpkgs-unstable 54
    • nixos-unstable-small 54
  • nixos-25.11 -
    • nixos-25.11-small 54
    • nixpkgs-25.11-darwin 54
  • nixos-25.05 52
    • nixos-25.05-small 52
    • nixpkgs-25.05-darwin 52

pkgs.python312Packages.lunarcalendar

Lunar-Solar Converter, containing a number of lunar and solar festivals in China

pkgs.python313Packages.lunarcalendar

Lunar-Solar Converter, containing a number of lunar and solar festivals in China

pkgs.python314Packages.lunarcalendar

Lunar-Solar Converter, containing a number of lunar and solar festivals in China

pkgs.home-assistant-component-tests.lunatone

Open source home automation that puts local control and privacy first

pkgs.python312Packages.korean-lunar-calendar

Library to convert Korean lunar-calendar to Gregorian calendar

pkgs.python313Packages.korean-lunar-calendar

Library to convert Korean lunar-calendar to Gregorian calendar

pkgs.python314Packages.korean-lunar-calendar

Library to convert Korean lunar-calendar to Gregorian calendar

pkgs.gnomeExtensions.luna-moon-phase-indicator

Luna is a simple GNOME Shell extension that displays the current moon phase directly in your top bar. With beautiful custom icons and real-time updates, Luna helps you stay attuned to lunar cycles throughout your day.

  • nixos-unstable 4
    • nixpkgs-unstable 4
    • nixos-unstable-small 4
  • nixos-25.11 -
    • nixos-25.11-small 4
    • nixpkgs-25.11-darwin 4
  • nixos-25.05 4
    • nixos-25.05-small 4
    • nixpkgs-25.05-darwin 4

pkgs.python312Packages.lunatone-rest-api-client

Client library for accessing the Lunatone REST API

pkgs.python313Packages.lunatone-rest-api-client

Client library for accessing the Lunatone REST API

pkgs.python314Packages.lunatone-rest-api-client

Client library for accessing the Lunatone REST API

pkgs.tests.home-assistant-component-tests.lunatone

Open source home automation that puts local control and privacy first

created 20 hours ago
HCL AION is susceptible to Missing SameSite vulnerability

HCL AION is affected by a Cookie with Insecure, Improper, or Missing SameSite vulnerability. This can allow cookies to be sent in cross-site requests, potentially increasing exposure to cross-site request forgery and related security risks. This issue affects AION: 2.0.

Affected products

AION
  • ==2.0

Matching in nixpkgs

pkgs.python312Packages.aionut

Asyncio Network UPS Tools

pkgs.python314Packages.aionut

Asyncio Network UPS Tools

pkgs.python312Packages.aiontfy

Async ntfy client library

pkgs.python314Packages.aiontfy

Async ntfy client library

pkgs.python312Packages.aionanoleaf

Python wrapper for the Nanoleaf API

pkgs.python314Packages.aionanoleaf

Python wrapper for the Nanoleaf API

pkgs.python312Packages.electrum-aionostr

Asyncio nostr client

pkgs.python313Packages.electrum-aionostr

Asyncio nostr client

pkgs.python314Packages.electrum-aionostr

Asyncio nostr client

Package maintainers

created 20 hours ago
Moodle: moodle: cross-site scripting (xss) via improper sanitization of ai prompt responses

A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, caused by improper sanitization of AI prompt responses, allows attackers to inject malicious HTML or script into web pages. When other users view these compromised pages, their sessions could be stolen, or the user interface could be manipulated.

Affected products

moodle
  • <5.0.4
  • <5.1.1
  • <4.5.8

Matching in nixpkgs

pkgs.moodle

Free and open-source learning management system (LMS) written in PHP

Package maintainers