Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
created 2 months ago Activity log
  • Created suggestion
XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 …

XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via a crafted XML document.

References

Affected products

Jenkins
  • ==before 1.600
Jenkins LTS
  • ==before 1.596.1

Matching in nixpkgs

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git

Permalink CVE-2026-25595
4.8 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): HIGH
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
created 2 months ago Activity log
  • Created suggestion
InvoicePlane has Stored XSS via Invoice Number in Invoice View and Dashboard

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability exists in InvoicePlane 1.7.0 via the Invoice Number field. An authenticated administrator can inject malicious JavaScript that executes when any administrator views the affected invoice or visits the dashboard. Version 1.7.1 patches the issue.

Affected products

InvoicePlane
  • ==<= 1.7.0

Matching in nixpkgs

pkgs.invoiceplane

Self-hosted open source application for managing your invoices, clients and payments

Package maintainers

created 2 months ago Activity log
  • Created suggestion
A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and …

A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names.

Affected products

MediaWiki
  • ==before 1.19.5 and 1.20.x before 1.20.4

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Monkey HTTP Daemon has local security bypass

Monkey HTTP Daemon has local security bypass

Affected products

monkey
  • ==through 2013-06-14

Matching in nixpkgs

pkgs.monkeysphere

Leverage the OpenPGP web of trust for SSH and TLS authentication

  • nixos-unstable 0.44
    • nixpkgs-unstable 0.44
    • nixos-unstable-small 0.44
  • nixos-25.11 0.44
    • nixos-25.11-small 0.44
    • nixpkgs-25.11-darwin 0.44

pkgs.gnomeExtensions.monkeybar

See your weekly Monkeytype typing activity in top bar

  • nixos-unstable 9
    • nixpkgs-unstable 9
    • nixos-unstable-small 9
  • nixos-25.11 4
    • nixos-25.11-small 4
    • nixpkgs-25.11-darwin 4

pkgs.python312Packages.monkeyhex

Small library to assist users of the python shell who work in contexts where printed numbers are more usefully viewed in hexadecimal

Package maintainers

Permalink CVE-2026-25548
9.1 CRITICAL
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): HIGH
  • User interaction (UI): NONE
  • Scope (S): CHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 2 months ago Activity log
  • Created suggestion
InvoicePlane Vulnerable to Remote Code Execution via Local File Inclusion and Log Poisoning

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Code Execution (RCE) vulnerability exists in InvoicePlane 1.7.0 through a chained Local File Inclusion (LFI) and Log Poisoning attack. An authenticated administrator can execute arbitrary system commands on the server by manipulating the `public_invoice_template` setting to include poisoned log files containing PHP code. Version 1.7.1 patches the issue.

Affected products

InvoicePlane
  • ==<= 1.7.0

Matching in nixpkgs

pkgs.invoiceplane

Self-hosted open source application for managing your invoices, clients and payments

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and …

Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and earlier, Exaquantum/Batch R2.50.30 and earlier, Exapilot R3.96.10 and earlier, Exaplog R3.40.00 and earlier, Exasmoc R4.03.20 and earlier, Exarqe R4.03.20 and earlier, Field Wireless Device OPC Server R2.01.02 and earlier, PRM R3.12.00 and earlier, STARDOM VDS R7.30.01 and earlier, STARDOM OPC Server for Windows R3.40 and earlier, FAST/TOOLS R10.01 and earlier, B/M9000CS R5.05.01 and earlier, B/M9000 VP R7.03.04 and earlier, and FieldMate R1.01 or R1.02 allows remote attackers to cause a denial of service (process outage) via a crafted packet.

References

Affected products

PRM
  • ==R3.12.00 and earlier
Exaopc
  • ==R3.72.00 and earlier
Exarqe
  • ==R4.03.20 and earlier
Exaplog
  • ==R3.40.00 and earlier
Exasmoc
  • ==R4.03.20 and earlier
Exapilot
  • ==R3.96.10 and earlier
B/M9000CS
  • ==R5.05.01 and earlier
CENTUM VP
  • ==R5.04.20 and earlier
FieldMate
  • ==R1.01
  • ==R1.02
B/M9000 VP
  • ==R7.03.04 and earlier
Exaquantum
  • ==R2.85.00 and earlier
FAST/TOOLS
  • ==R10.01 and earlier
ProSafe-RS
  • ==R3.02.10 and earlier
STARDOM VDS
  • ==R7.30.01 and earlier
CENTUM CS 1000
  • ==R3.08.70 and earlier
CENTUM CS 3000
  • ==R3.09.50 and earlier
CENTUM VP Entry
  • ==R5.04.20 and earlier
Exaquantum/Batch
  • ==R2.50.30 and earlier
CENTUM CS 3000 Entry
  • ==R3.09.50 and earlier
STARDOM OPC Server for Windows
  • ==R3.40 and earlier
Field Wireless Device OPC Server
  • ==R2.01.02 and earlier

Matching in nixpkgs

pkgs.prmt

Ultra-fast, customizable shell prompt generator

pkgs.hyprmon

TUI monitor configuration tool for Hyprland with visual layout, drag-and-drop, and profile management

Package maintainers

Permalink CVE-2026-2665
6.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
created 2 months ago Activity log
  • Created suggestion
huanzi-qch base-admin JSP Parser SysFileController.java upload unrestricted upload

A vulnerability was detected in huanzi-qch base-admin up to 57a8126bb3353a004f3c7722089e3b926ea83596. Impacted is the function Upload of the file SysFileController.java of the component JSP Parser. Performing a manipulation of the argument File results in unrestricted upload. The attack can be initiated remotely. The exploit is now public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

base-admin
  • ==57a8126bb3353a004f3c7722089e3b926ea83596

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
xnview.exe in XnView before 2.13 does not properly handle RLE …

xnview.exe in XnView before 2.13 does not properly handle RLE strip lengths during processing of RGB files, which allows remote attackers to execute arbitrary code via the RLE strip size field in a RGB file, which leads to an unexpected sign extension error and a heap-based buffer overflow.

References

Affected products

XnView
  • ==before 2.13

Matching in nixpkgs

pkgs.xnviewmp

Efficient multimedia viewer, browser and converter

Package maintainers

created 2 months ago Activity log
  • Created suggestion
duplicity 0.6.24 has improper verification of SSL certificates

duplicity 0.6.24 has improper verification of SSL certificates

Affected products

duplicity
  • ==0.6.24

Matching in nixpkgs

pkgs.duplicity

Encrypted bandwidth-efficient backup using the rsync algorithm

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Vulnerability in FileUtils v0.7, Ruby Gem Fileutils <= v0.7 Command …

Vulnerability in FileUtils v0.7, Ruby Gem Fileutils <= v0.7 Command Injection vulnerability in user supplied url variable that is passed to the shell.

References

Affected products

FileUtils
  • =<0.7

Matching in nixpkgs

pkgs.mpifileutils

Suite of MPI-based tools to manage large datasets

  • nixos-unstable 0.12
    • nixpkgs-unstable 0.12
    • nixos-unstable-small 0.12
  • nixos-25.11 0.12
    • nixos-25.11-small 0.12
    • nixpkgs-25.11-darwin 0.12

Package maintainers