CVE-2025-61557 Details
Description
nixseparatedebuginfod before v0.4.1 is vulnerable to Directory Traversal.
A directory traversal vulnerability has been identified in nixseparatedebuginfod versions prior to 0.4.1. This vulnerability allows a client to request source files from paths outside the Nix store, potentially disclosing the contents of any readable file on the system. The issue arises because nixseparatedebuginfod does not properly validate file paths before serving them. While the impact is generally limited to world-readable files when using the NixOS module, more severe consequences can occur if nixseparatedebuginfod is run manually or exposed to the internet.
Users can update to nixseparatedebuginfod version 0.4.1 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| symphorien nixseparatedebuginfod | < 0.4.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 14, 2026 | Initial Analysis | [email protected] |
| Jan 2, 2026 | CVE Modified | CISA-ADP |
| Dec 30, 2025 | New CVE Received | [email protected] |