CVE-2026-44029

EUVD-2026-27166
An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "nix store prefetch-file --unpack" directory traversal. The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 (introduced in 2.24.7);
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
mitreCNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 47%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
nixosnix
2.24.7 ≤
𝑥
< 2.28.7
CNA
nixosnix
2.29.0 ≤
𝑥
< 2.29.4
CNA
nixosnix
2.30.0 ≤
𝑥
< 2.30.5
CNA
nixosnix
2.31.0 ≤
𝑥
< 2.31.5
CNA
nixosnix
2.32.0 ≤
𝑥
< 2.32.8
CNA
nixosnix
2.33.0 ≤
𝑥
< 2.33.6
CNA
nixosnix
2.34.0 ≤
𝑥
< 2.34.7
CNA
Debian logo
Debian Releases
Debian Product
Codename
nix
bookworm
2.8.0-1.1
fixed
bullseye
vulnerable
forky
vulnerable
sid
vulnerable
trixie
vulnerable