CVE-2019-17365: Nixos Nix
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Nix through 2.3 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable.
Affected products
- Nixos Nix: up to and including 2.3
Published 2019-10-09. Last modified 2026-06-17.