Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 05 May 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 May 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Directory Traversal in Nix Prefetch Commands Allowing Local Arbitrary File Write |
Tue, 05 May 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "nix store prefetch-file --unpack" directory traversal. The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 (introduced in 2.24.7); | |
| First Time appeared |
Nixos
Nixos nix |
|
| Weaknesses | CWE-36 | |
| CPEs | cpe:2.3:a:nixos:nix:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nixos
Nixos nix |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-05T12:43:28.239Z
Reserved: 2026-05-05T00:51:05.139Z
Link: CVE-2026-44029
Updated: 2026-05-05T12:43:23.712Z
Status : Deferred
Published: 2026-05-05T01:16:07.170
Modified: 2026-05-05T19:47:31.297
Link: CVE-2026-44029
No data.
OpenCVE Enrichment
Updated: 2026-05-05T03:00:10Z