An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "nix store prefetch-file --unpack" directory traversal. The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 (introduced in 2.24.7);
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 05 May 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "nix store prefetch-file --unpack" directory traversal. The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 (introduced in 2.24.7); | |
| First Time appeared |
Nixos
Nixos nix |
|
| Weaknesses | CWE-36 | |
| CPEs | cpe:2.3:a:nixos:nix:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nixos
Nixos nix |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-05T00:58:14.984Z
Reserved: 2026-05-05T00:51:05.139Z
Link: CVE-2026-44029
No data.
Status : Received
Published: 2026-05-05T01:16:07.170
Modified: 2026-05-05T01:16:07.170
Link: CVE-2026-44029
No data.
OpenCVE Enrichment
Updated: 2026-05-05T02:30:13Z
Weaknesses