Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestions search

With package: python314Packages.llm-lmstudio

Found 5 matching suggestions

View:
Compact
Detailed
created 1 week, 3 days ago
Frappe Learning Management System has Client-Side Manipulation of Quiz Scores

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.46.0, a vulnerability has been identified in Frappe Learning where quiz scores can be modified by students before submission. The application currently relies on client-side calculated scores, which can be altered using browser developer tools prior to sending the submission request. While this does not allow modification of other users’ data or privilege escalation, it compromises the integrity of quiz results and undermines academic reliability. This issue affects data integrity but does not expose confidential information or allow unauthorized access to other accounts. This vulnerability is fixed in 2.46.0.

Affected products

lms
  • ==< 2.46.0

Matching in nixpkgs

pkgs.lms

Lightweight Music Server - Access your self-hosted music using a web interface

pkgs.helmsman

Helm Charts (k8s applications) as Code tool

pkgs.lmstudio

LM Studio is an easy to use desktop app for experimenting with local and open-source Large Language Models (LLMs)

Package maintainers

created 2 weeks, 2 days ago
Stored XSS in Frappe LMS

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. From version 2.27.0 to before version 2.48.0, Frappe LMS was vulnerable to stored XSS. This issue has been patched in version 2.48.0.

Affected products

lms
  • ==>= 2.27.0, < 2.48.0

Matching in nixpkgs

pkgs.lms

Lightweight Music Server - Access your self-hosted music using a web interface

pkgs.helmsman

Helm Charts (k8s applications) as Code tool

pkgs.lmstudio

LM Studio is an easy to use desktop app for experimenting with local and open-source Large Language Models (LLMs)

Package maintainers

created 1 month, 4 weeks ago
Frappe Learning Management System exposes details of unpublished courses to unauthorized users

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.44.0 and below, unauthorized users are able to access the details of unpublished courses via API endpoints. A fix for this issue is planned for the 2.45.0 release.

Affected products

lms
  • ==<= 2.44.0

Matching in nixpkgs

pkgs.lms

Lightweight Music Server - Access your self-hosted music using a web interface

pkgs.helmsman

Helm Charts (k8s applications) as Code tool

pkgs.lmstudio

LM Studio is an easy to use desktop app for experimenting with local and open-source Large Language Models (LLMs)

Package maintainers

created 2 months, 1 week ago
Frappe LMS affected by unauthorised user was able to access the full list of batch enrolled students

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.44.0, security issue was identified in Frappe Learning, where unauthorised users were able to access the full list of enrolled students (by email) in batches. This vulnerability is fixed in 2.44.0.

Affected products

lms
  • ==< 2.44.0

Matching in nixpkgs

pkgs.lms

Lightweight Music Server - Access your self-hosted music using a web interface

pkgs.helmsman

Helm Charts (k8s applications) as Code tool

pkgs.lmstudio

LM Studio is an easy to use desktop app for experimenting with local and open-source Large Language Models (LLMs)

Package maintainers

Permalink CVE-2019-25276
7.8 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 2 months, 2 weeks ago
Studio 5000 Logix Designer 30.01.00 - 'FactoryTalk Activation Service' Unquoted Service Path

Studio 5000 Logix Designer 30.01.00 contains an unquoted service path vulnerability in the FactoryTalk Activation Service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Rockwell Software\FactoryTalk Activation\ to inject malicious code that would execute with LocalSystem permissions.

Affected products

Studio
  • ==5000

Matching in nixpkgs

pkgs.lmstudio

LM Studio is an easy to use desktop app for experimenting with local and open-source Large Language Models (LLMs)

pkgs.texstudio

TeX and LaTeX editor

  • nixos-unstable -
  • nixos-25.11 4.9.0

pkgs.obs-studio

Free and open source software for video recording and live streaming

  • nixos-unstable -
  • nixos-25.11 32.0.1

pkgs.sql-studio

SQL Database Explorer [SQLite, libSQL, PostgreSQL, MySQL/MariaDB, ClickHouse, Microsoft SQL Server]

  • nixos-unstable -
  • nixos-25.11 0.1.45

pkgs.zmk-studio

Tool for runtime keymap updates on ZMK-powered devices without reflashing firmware

  • nixos-unstable -

pkgs.realm-studio

Visual tool to view, edit, and model Realm databases.

  • nixos-unstable -
  • nixos-25.11 15.2.1

pkgs.sqlitestudio

Free, open source, multi-platform SQLite database manager

  • nixos-unstable -
  • nixos-25.11 3.4.17

pkgs.cherry-studio

Desktop client that supports for multiple LLM providers

  • nixos-unstable -
  • nixos-25.11 1.6.7

pkgs.lutgen-studio

Official GUI for Lutgen, the best way to apply popular colorschemes to any image or wallpaper

  • nixos-unstable -
  • nixos-25.11 0.3.0

pkgs.azuredatastudio

Data management tool that enables working with SQL Server, Azure SQL DB and SQL DW

  • nixos-unstable -
  • nixos-25.11 1.49.1

pkgs.beekeeper-studio

Modern and easy to use SQL client for MySQL, Postgres, SQLite, SQL Server, and more

  • nixos-unstable -
  • nixos-25.11 5.3.4

pkgs.sourcepawn-studio

LSP implementation for the SourcePawn programming language written in Rust

  • nixos-unstable -
  • nixos-25.11 8.1.8

pkgs.cups-toshiba-estudio

Printer only driver for the Toshiba e-STUDIO class of printers

  • nixos-unstable -
    • nixpkgs-unstable 7.89
  • nixos-25.11 7.89

pkgs.sqlitestudio-plugins

Official plugins for SQLiteStudio, a free, open source, multi-platform SQLite database manager

  • nixos-unstable -
  • nixos-25.11 3.4.17

Package maintainers