CVE-2025-64766

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-64766
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-64766.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-64766
Aliases
  • GHSA-58m4-5wg3-5g5v
Published
2025-11-17T21:38:10.023Z
Modified
2025-12-05T11:10:59.836175Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
NixOS has hardcoded credentials in Onlyoffice module
Details

NixOS's Onlyoffice is a software suite that offers online and offline tools for document editing, collaboration, and management. In versions from 22.11 to before 25.05 and versions before Unstable 25.11, a hard-coded secret was used in the NixOS module for the OnlyOffice document server to protect its file cache. An attacker with knowledge of an existing revision ID could use this secret to obtain a document. In practice, an arbitrary revision ID should be hard to obtain. The primary impact is likely the access to known documents from users with expired access. This issue was resolved in NixOS unstable version 25.11 and version 25.05.

Database specific
{
    "cwe_ids": [
        "CWE-798"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64766.json"
}
References

Affected packages

Git / github.com/nixos/nixpkgs

Affected ranges

Type
GIT
Repo
https://github.com/nixos/nixpkgs
Events
Database specific
{
    "versions": [
        {
            "introduced": "22.11"
        },
        {
            "fixed": "25.05"
        }
    ]
}
Type
GIT
Repo
https://github.com/nixos/nixpkgs
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "Unstable25.11"
        }
    ]
}

Affected versions

0.*

0.1
0.13
0.14
0.2
0.3
0.4

15.*

15.09-beta

16.*

16.09-beta

17.*

17.09-beta

18.*

18.03-beta
18.09-beta

21.*

21.11-pre

22.*

22.05-pre

23.*

23.05-pre
23.11-beta
23.11-pre

24.*

24.05-pre
24.11-pre

Other

binary
black@2016-05-13
v192
v206
v208

last-glibc-2.*

last-glibc-2.13

release-16.*

release-16.03-start