Nixpkgs security tracker

Login with GitHub

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
Permalink CVE-2026-24078
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Adjacent (A)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Adjacent (A)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 54 minutes ago Activity log
  • Created suggestion
Exposure of Private Personal Information to an Unauthorized Actor in Data Modem

Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.

Affected products

Snapdragon
  • ==Snapdragon 888 5G Mobile Platform
  • ==QCN9024
  • ==SM7435
  • ==Snapdragon 6 Gen 4 Mobile Platform
  • ==AR8035
  • ==FastConnect 6700
  • ==SM7550
  • ==Snapdragon 7+ Gen 2 Mobile Platform
  • ==QCA6174A
  • ==QCA6698AU
  • ==Snapdragon 4 Gen 1 Mobile Platform
  • ==SW5100
  • ==5G Fixed Wireless Access Platform
  • ==FastConnect 6800
  • ==Robotics RB2 Platform
  • ==WCD9340
  • ==QCA6696
  • ==QCA6595AU
  • ==Snapdragon 4 Gen 2 Mobile Platform
  • ==FastConnect 6900
  • ==Netrani
  • ==WSA8835
  • ==Snapdragon 8 Elite
  • ==SM7635P
  • ==SM8635P
  • ==WCN3950
  • ==QCN9012
  • ==SM8550P
  • ==Snapdragon 865 5G Mobile Platform
  • ==WCD9370
  • ==FastConnect 6200
  • ==QFW7114
  • ==SM7675
  • ==WCN6755
  • ==SM8650Q
  • ==QCS4490
  • ==Snapdragon 7 Gen 1 Mobile Platform
  • ==Snapdragon 778G 5G Mobile Platform
  • ==FSM20055
  • ==Snapdragon X32 5G Modem-RF System
  • ==Snapdragon 695 5G Mobile Platform
  • ==Snapdragon 782G Mobile Platform
  • ==FastConnect 7800
  • ==QCA6584AU
  • ==QCM4490
  • ==WSA8815
  • ==WCN3910
  • ==WCN7880
  • ==QCM6490
  • ==Snapdragon Auto 5G Modem-RF Gen 2
  • ==Themisto
  • ==WCN6650
  • ==WSA8845
  • ==Snapdragon 8+ Gen 2 Mobile Platform
  • ==Milos
  • ==Snapdragon 778G+ 5G Mobile Platform
  • ==QCN6224
  • ==Snapdragon 480+ 5G Mobile Platform
  • ==QCM2290
  • ==Snapdragon 662 Mobile Platform
  • ==SW6100P
  • ==WCD9378
  • ==QCC710
  • ==Snapdragon 870 5G Mobile Platform
  • ==QCS2290
  • ==QCM5430
  • ==SM6650P
  • ==Snapdragon X53 5G Modem-RF System
  • ==SM6225P
  • ==Snapdragon 6 Gen 1 Mobile Platform
  • ==Snapdragon 7c+ Gen 3 Compute
  • ==Snapdragon 888+ 5G Mobile Platform
  • ==WSA8840
  • ==QCA6688AQ
  • ==Snapdragon 865+ 5G Mobile Platform
  • ==QCA6698AQ
  • ==WCD9375
  • ==WCD9390
  • ==SM8750P
  • ==QCA8337
  • ==Snapdragon 6 Gen 3 Mobile Platform
  • ==SDX57M
  • ==SW6100
  • ==SM7675P
  • ==QCA6574AU
  • ==Snapdragon 8+ Gen 1 Mobile Platform
  • ==SM8475P
  • ==SW5100P
  • ==QCN6024
  • ==Snapdragon 480 5G Mobile Platform
  • ==QMP1000
  • ==Palawan25
  • ==Snapdragon 8 Gen 2 Mobile Platform
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==QCN6274
  • ==QCA8081
  • ==WSA8832
  • ==WCD9360
  • ==Snapdragon 690 5G Mobile Platform
  • ==Snapdragon 685 4G Mobile Platform
  • ==WCD9395
  • ==Snapdragon X75 5G Modem-RF System
  • ==WCN7860
  • ==WCD9335
  • ==QCN9011
  • ==SM7325P
  • ==CSRA6640
  • ==FWA Gen 3 Ultra Platform
  • ==QCS8550
  • ==SM8635
  • ==Snapdragon 8 Gen 1 Mobile Platform
  • ==SM7550P
  • ==WCN3980
  • ==FSM200 Platform
  • ==SDX61
  • ==WCN7881
  • ==WSA8830
  • ==CSRA6620
  • ==QEP8111
  • ==WCD9380
  • ==Snapdragon X35 5G Modem-RF System
  • ==G1 Gen 1
  • ==QCS4290
  • ==WSA8810
  • ==QCM4325
  • ==Snapdragon Auto 5G Modem-RF
  • ==Snapdragon 680 4G Mobile Platform
  • ==QCA6391
  • ==WCN3988
  • ==QCA6574A
  • ==WCD9385
  • ==Snapdragon X72 5G Modem-RF System
  • ==QFW7124
  • ==QCA6678AQ
  • ==QCA6797AQ
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==Snapdragon X65 5G Modem-RF System
  • ==Snapdragon 460 Mobile Platform
  • ==Snapdragon X55 5G Modem-RF System
  • ==Orne
  • ==SD662
  • ==Snapdragon W5+ Gen 1 Wearable Platform
  • ==WCD9371
  • ==WCN7861
  • ==WSA8845H
  • ==SD 8 Gen1 5G
  • ==Snapdragon 7s Gen 3 Mobile Platform

Matching in nixpkgs

Permalink CVE-2026-24084
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 54 minutes ago Activity log
  • Created suggestion
Insecure Security Identifier Mechanism in Multi-Mode Call Processor

Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.

Affected products

Snapdragon
  • ==Snapdragon 888 5G Mobile Platform
  • ==QCN9024
  • ==SM7435
  • ==Snapdragon 6 Gen 4 Mobile Platform
  • ==AR8035
  • ==FastConnect 6700
  • ==SnapdragonAuto 4GModem
  • ==SM7550
  • ==Snapdragon 7+ Gen 2 Mobile Platform
  • ==QCA6174A
  • ==QCA6698AU
  • ==Snapdragon 4 Gen 1 Mobile Platform
  • ==5G Fixed Wireless Access Platform
  • ==FastConnect 6800
  • ==WCD9340
  • ==QCA6696
  • ==QCA6595AU
  • ==Snapdragon 4 Gen 2 Mobile Platform
  • ==FastConnect 6900
  • ==Netrani
  • ==WSA8835
  • ==Snapdragon 8 Elite
  • ==SM7635P
  • ==SM8635P
  • ==WCN3950
  • ==QCN9012
  • ==SM8550P
  • ==Snapdragon 865 5G Mobile Platform
  • ==WCD9370
  • ==WCD9341
  • ==Snapdragon X80 5G Modem-RF System
  • ==FastConnect 6200
  • ==QFW7114
  • ==SM7675
  • ==WCN6755
  • ==SM8650Q
  • ==QCS4490
  • ==Snapdragon 7 Gen 1 Mobile Platform
  • ==Snapdragon 778G 5G Mobile Platform
  • ==Snapdragon 8cx Compute Platform
  • ==Snapdragon 695 5G Mobile Platform
  • ==Snapdragon 782G Mobile Platform
  • ==Snapdragon 8c Compute Platform "Poipu Lite"
  • ==FastConnect 7800
  • ==QCA6584AU
  • ==QCM4490
  • ==WSA8815
  • ==WCN7880
  • ==QCM6490
  • ==Snapdragon Auto 5G Modem-RF Gen 2
  • ==WCN6650
  • ==QCA6420
  • ==Snapdragon 8+ Gen 2 Mobile Platform
  • ==WSA8845
  • ==Milos
  • ==Snapdragon 778G+ 5G Mobile Platform
  • ==QCN6224
  • ==Snapdragon 480+ 5G Mobile Platform
  • ==WCD9378
  • ==QCC710
  • ==Snapdragon 870 5G Mobile Platform
  • ==QCM5430
  • ==SM6650P
  • ==Snapdragon X53 5G Modem-RF System
  • ==Snapdragon 888+ 5G Mobile Platform
  • ==Snapdragon 6 Gen 1 Mobile Platform
  • ==Snapdragon 7c+ Gen 3 Compute
  • ==WSA8840
  • ==QCA6688AQ
  • ==Snapdragon 865+ 5G Mobile Platform
  • ==QCA6698AQ
  • ==WCD9375
  • ==WCD9390
  • ==SM8750P
  • ==QCA8337
  • ==Snapdragon 6 Gen 3 Mobile Platform
  • ==SDX57M
  • ==SM7675P
  • ==QCA6574AU
  • ==Snapdragon 8+ Gen 1 Mobile Platform
  • ==SM8475P
  • ==QCN6024
  • ==Snapdragon 480 5G Mobile Platform
  • ==QMP1000
  • ==Palawan25
  • ==Snapdragon 8 Gen 2 Mobile Platform
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==SDX71M
  • ==Snapdragon 8cx Gen 2 5G Compute Platform "Poipu Pro"
  • ==QCN6274
  • ==QCA8081
  • ==Snapdragon X70 Modem-RF System
  • ==WSA8832
  • ==Snapdragon 690 5G Mobile Platform
  • ==QCA6430
  • ==WCD9395
  • ==Snapdragon X75 5G Modem-RF System
  • ==WCN7860
  • ==QCN9011
  • ==SM7325P
  • ==FWA Gen 3 Ultra Platform
  • ==AQT1000
  • ==QCS8550
  • ==SM8635
  • ==SM7550P
  • ==Snapdragon 8 Gen 1 Mobile Platform
  • ==SDX61
  • ==WCN7881
  • ==WSA8830
  • ==WCD9380
  • ==WSA8810
  • ==Snapdragon Auto 5G Modem-RF
  • ==QCA6391
  • ==WCN3988
  • ==WCD9385
  • ==Snapdragon X72 5G Modem-RF System
  • ==QFW7124
  • ==QCA6678AQ
  • ==QCA6797AQ
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==Snapdragon X65 5G Modem-RF System
  • ==Snapdragon X55 5G Modem-RF System
  • ==Orne
  • ==WCD9371
  • ==WCN7861
  • ==SD 8 Gen1 5G
  • ==WSA8845H
  • ==Snapdragon 7s Gen 3 Mobile Platform

Matching in nixpkgs

Permalink CVE-2026-47612
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 54 minutes ago Activity log
  • Created suggestion
NVIDIA Dynamo for Linux contains a vulnerability in the image …

NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A successful exploit of this vulnerability might lead to information disclosure.

Affected products

Dynamo
  • ==0 to v1.0.0

Matching in nixpkgs

pkgs.dynamodb-local

DynamoDB Local is a small client-side database and server that mimics the DynamoDB service

Package maintainers

Permalink CVE-2026-18739
2.5 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
created 55 minutes ago Activity log
  • Created suggestion
Popt-devel: popt-static: off-by-one in poptstuffargs

A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.

References

Affected products

popt
rhcos

Matching in nixpkgs

pkgs.popt

Command line option parsing library

  • nixos-unstable 1.19
    • nixpkgs-unstable 1.19
    • nixos-unstable-small 1.19
  • nixos-26.05 1.19
    • nixos-26.05-small 1.19
    • nixpkgs-26.05-darwin 1.19

pkgs.poptop

Modern top command that charts system metrics like CPU load, network IO, etc in the terminal

pkgs.scipopt-ug

Ubiquity Generator framework to parallelize branch-and-bound based solvers

pkgs.scipopt-gcg

Branch-and-Price & Column Generation for Everyone

Permalink CVE-2026-70594
6.7 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Adjacent (A)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Adjacent (A)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): Low (L)
created 55 minutes ago Activity log
  • Created suggestion
Ghost: Session Fixation in Ghost Admin

Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the same domain where Ghost Admin was hosted. This issue is fixed in version 6.54.1.

Affected products

Ghost
  • ==>= 2.2.0, < 6.54.1

Matching in nixpkgs

pkgs.ghostie

Github notifications in your terminal

pkgs.ghostty

Fast, native, feature-rich terminal emulator pushing modern features

pkgs.ghostunnel

TLS proxy with mutual authentication support for securing non-TLS backend applications

pkgs.ghostty-bin

Fast, native, feature-rich terminal emulator pushing modern features

pkgs.ghost-complete

Terminal-native autocomplete engine using PTY proxying for macOS terminals

Package maintainers

Permalink CVE-2026-70493
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 55 minutes ago Activity log
  • Created suggestion
Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built-in knowledge search path in backend/open_webui/tools/knowledge_fs.py and backend/open_webui/tools/builtin.py let a chat participant choose a pattern used to grep knowledge files. Patterns containing regex metacharacters were compiled with Python's backtracking re engine and run against every line of every reachable file with no time limit, so a crafted pattern such as (x|x)*y and one matching uploaded file line can pin one CPU core and block the event loop. This causes availability impact for every other user of the affected worker. This issue is fixed in 0.11.0.

Affected products

open-webui
  • ==>= 0.9.6, < 0.11.0

Matching in nixpkgs

pkgs.open-webui

Comprehensive suite for LLMs with a user-friendly WebUI

Package maintainers

Permalink CVE-2026-13229
7.1 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 55 minutes ago Activity log
  • Created suggestion
Zammad 7.0.1 - Improper authorization in ticket article attachment cloning

Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint.

Affected products

Zammad
  • =<7.0.1

Matching in nixpkgs

pkgs.zammad

Web-based, open source user support/ticketing solution

Package maintainers

Permalink CVE-2026-70481
5.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
created 55 minutes ago Activity log
  • Created suggestion
Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any caller holding write access on the channel without checking that the caller wrote the message. Because write access is the same grant a member needs to post, any ordinary participant in a shared standard channel could rewrite or permanently delete another participant message, while group and direct message handlers enforced authorship. This issue is fixed in 0.11.0.

Affected products

open-webui
  • ==>= 0.5.0, < 0.11.0

Matching in nixpkgs

pkgs.open-webui

Comprehensive suite for LLMs with a user-friendly WebUI

Package maintainers

Permalink CVE-2026-68585
6.9 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): Low (L)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Low (L)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 day ago Activity log
  • Created suggestion
SiYuan before v3.7.3 Metadata Disclosure via getBlockInfo

SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that returns document root metadata including title for publish-forbidden documents without publish-access checks. Anonymous readers or publish RoleReader tokens can supply a block ID to retrieve the title, notebook, path, root ID, and icon of documents administrators marked as excluded from publishing.

Affected products

siyuan
  • <3.7.3
  • ==3.7.3

Matching in nixpkgs

pkgs.siyuan

Privacy-first personal knowledge management system that supports complete offline usage, as well as end-to-end encrypted data sync

Package maintainers

Permalink CVE-2026-18737
7.1 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 day ago Activity log
  • Created suggestion
Shlink Blind SQL Injection via tags/stats orderBy Parameter

Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL fragments by supplying an unvalidated direction value in the orderBy query parameter of the tag statistics endpoint. Attackers can craft a malicious direction string containing SQL subqueries that flows unsanitized into a Doctrine QueryBuilder ORDER BY clause, enabling time-based, boolean-oracle, and error-based extraction of sensitive data including long URLs, visitor records, IP addresses, geolocation data, user agents, and hashed API key secrets from any tenant.

Affected products

Shlink
  • =<5.1.5

Matching in nixpkgs

Package maintainers