Elevated Privileges Vulnerability in Nix Package Manager for macOS
CVE-2025-53819

7.9HIGH

Key Information:

Vendor

Nixos

Status
Vendor
CVE Published:
14 July 2025

What is CVE-2025-53819?

An elevated privileges vulnerability has been identified in the Nix package manager for macOS, specifically impacting builds created with Nix version 2.30.0. This vulnerability allows builds to be executed with root privileges, bypassing the intended user restrictions and posing significant security risks. A fix has been integrated in Nix version 2.30.1, and users are advised to upgrade to this version promptly as no workarounds are available to mitigate the issue.

Affected Version(s)

nix = 2.30.0

References

CVSS V3.1

Score:
7.9
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53819 : Elevated Privileges Vulnerability in Nix Package Manager for macOS