OnlyOffice Document Server Vulnerability in NixOS Software Suite
CVE-2025-64766
5.3MEDIUM
What is CVE-2025-64766?
In the NixOS's OnlyOffice software suite, versions from 22.11 to just before 25.05 and prior to Unstable 25.11 were found to contain a hard-coded secret within its document server module. This secret was intended to secure the file cache but could potentially allow an attacker, who has knowledge of a specific revision ID, to access documents that should have been secured. The likelihood of obtaining an arbitrary revision ID is low, yet the risk could expose documents to unauthorized users, particularly impacting those with expired access permissions. This vulnerability was remediated in NixOS unstable version 25.11 and version 25.05.
Affected Version(s)
nixpkgs >= 22.11, < 25.05 < 22.11, 25.05
nixpkgs < Unstable 25.11 < Unstable 25.11
