Description

Hydra is a continuous integration service for Nix based projects. Prior to commit dea1e16, a malicious package can introduce arbitrary JavaScript code into the Hydra database that is automatically evaluated in a client's browser when anyone visits the build page. This could be done by a third-party project as part of its build process. This also happens in other places like with hydra-release-name. This issue has been patched by commit dea1e16. A workaround involves either not building untrusted packages or not visiting the builds page.

INFO

Published Date :

2025-08-12T15:47:11.337Z

Last Modified :

2025-08-12T15:57:41.274Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2025-54800 vulnerability.

Vendors Products
Nixos
  • Hydra
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-54800.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact