CVE-2019-18192: GNU Guix

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable, a similar issue to CVE-2019-17365.

Affected products

  • GNU Guix: version 1.0.1 only

Published 2019-10-17. Last modified 2026-06-17.