OnlyOffice Document Server Vulnerability in NixOS Software Suite
CVE-2025-64766

5.3MEDIUM

Key Information:

Vendor

Nixos

Status
Vendor
CVE Published:
17 November 2025

What is CVE-2025-64766?

In the NixOS's OnlyOffice software suite, versions from 22.11 to just before 25.05 and prior to Unstable 25.11 were found to contain a hard-coded secret within its document server module. This secret was intended to secure the file cache but could potentially allow an attacker, who has knowledge of a specific revision ID, to access documents that should have been secured. The likelihood of obtaining an arbitrary revision ID is low, yet the risk could expose documents to unauthorized users, particularly impacting those with expired access permissions. This vulnerability was remediated in NixOS unstable version 25.11 and version 25.05.

Affected Version(s)

nixpkgs >= 22.11, < 25.05 < 22.11, 25.05

nixpkgs < Unstable 25.11 < Unstable 25.11

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-64766 : OnlyOffice Document Server Vulnerability in NixOS Software Suite