CVE-2019-17365: Nixos Nix

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Nix through 2.3 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable.

Affected products

  • Nixos Nix: up to and including 2.3

Published 2019-10-09. Last modified 2026-06-17.