Arbitrary Code Execution Vulnerability in Hydra Continuous Integration Service
CVE-2025-54800

7.1HIGH

Key Information:

Vendor

Nixos

Status
Vendor
CVE Published:
12 August 2025

What is CVE-2025-54800?

The Hydra continuous integration service for Nix-based projects is susceptible to a vulnerability that allows the injection of arbitrary JavaScript code via malicious packages. When these packages are built, the injected code can be executed in the client's browser upon visiting the build page, potentially compromising user security. This vulnerability occurs during the build process of third-party projects and can also affect other areas like hydra-release-name. The issue has been mitigated in the system by a recent commit, and users are advised to avoid building untrusted packages or to refrain from accessing the builds page to safeguard their security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

hydra < dea1e168f590efb27db32dbacc82b09e15f8ae4b

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.