Privilege Escalation in Nix, Lix, and Guix Package Managers
CVE-2025-46416
2.9LOW
What is CVE-2025-46416?
The Nix, Lix, and Guix package managers exhibit a critical flaw that permits users to bypass build isolation mechanisms. This vulnerability allows unauthorized privilege escalation, enabling users to access the build user account, which could lead to potential exploitation. The affected versions span multiple releases across all three package managers, potentially allowing malicious actors to compromise the build environment.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Nix 0 <= 2.24.15
Nix 2.25.0 <= 2.26.4
Nix 2.27.0 <= 2.28.4
News Articles
References
CVSS V3.1
Score:
2.9
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
- đź“°
First article discovered by NixOS Discourse
Vulnerability Reserved
