Arbitrary Code Execution Vulnerability in Hydra Continuous Integration Service
CVE-2025-54800
What is CVE-2025-54800?
The Hydra continuous integration service for Nix-based projects is susceptible to a vulnerability that allows the injection of arbitrary JavaScript code via malicious packages. When these packages are built, the injected code can be executed in the client's browser upon visiting the build page, potentially compromising user security. This vulnerability occurs during the build process of third-party projects and can also affect other areas like hydra-release-name. The issue has been mitigated in the system by a recent commit, and users are advised to avoid building untrusted packages or to refrain from accessing the builds page to safeguard their security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
hydra < dea1e168f590efb27db32dbacc82b09e15f8ae4b
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
