CVE Explorer
CVE-2025-64766
NixOS's Onlyoffice is a software suite that offers online and offline tools for document editing, collaboration, and management. In versions from 22.11 to before 25.05 and versions before Unstable 25.11, a hard-coded secret was used in the NixOS module for the OnlyOffice document server to protect its file cache. An attacker with knowledge of an existing revision ID could use this secret to obtain a document. In practice, an arbitrary revision ID should be hard to obtain. The primary impact is l
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"nixpkgs","vendor":"NixOS","versions":[{"status":"affected","version":">= 22.11, < 25.05"},{"status":"affected","version":"< Unstable 25.11"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:108199207f5f20bc025b0f6c8d4a2b0de1e6471a4f7aae357d534677c927c552 · sha256:5f4a45e03d20db74… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:108199207f5f20bc025b0f6c8d4a2b0de1e6471a4f7aae357d534677c927c552 · sha256:5f4a45e03d20db74… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-798","description":"CWE-798: Use of Hard-coded Credentials","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:108199207f5f20bc025b0f6c8d4a2b0de1e6471a4f7aae357d534677c927c552 · sha256:5f4a45e03d20db74… · /containers/cna/problemTypes/0/descriptions/0
Source references
5 source assertions{"name":"https://github.com/NixOS/nixpkgs/commit/8e74d05e3de4ee5ad320cd585a7e0f12a4730869","tags":["x_refsource_MISC"],"url":"https://github.com/NixOS/nixpkgs/commit/8e74d05e3de4ee5ad320cd585a7e0f12a4730869"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:108199207f5f20bc025b0f6c8d4a2b0de1e6471a4f7aae357d534677c927c552 · sha256:5f4a45e03d20db74… · /containers/cna/references/3
{"name":"https://github.com/NixOS/nixpkgs/commit/cec38dec00df26a901eb8b424d53bbb3bcc72eec","tags":["x_refsource_MISC"],"url":"https://github.com/NixOS/nixpkgs/commit/cec38dec00df26a901eb8b424d53bbb3bcc72eec"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:108199207f5f20bc025b0f6c8d4a2b0de1e6471a4f7aae357d534677c927c552 · sha256:5f4a45e03d20db74… · /containers/cna/references/4
{"name":"https://github.com/NixOS/nixpkgs/pull/462100","tags":["x_refsource_MISC"],"url":"https://github.com/NixOS/nixpkgs/pull/462100"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:108199207f5f20bc025b0f6c8d4a2b0de1e6471a4f7aae357d534677c927c552 · sha256:5f4a45e03d20db74… · /containers/cna/references/1
{"name":"https://github.com/NixOS/nixpkgs/pull/462204","tags":["x_refsource_MISC"],"url":"https://github.com/NixOS/nixpkgs/pull/462204"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:108199207f5f20bc025b0f6c8d4a2b0de1e6471a4f7aae357d534677c927c552 · sha256:5f4a45e03d20db74… · /containers/cna/references/2
{"name":"https://github.com/NixOS/nixpkgs/security/advisories/GHSA-58m4-5wg3-5g5v","tags":["x_refsource_CONFIRM"],"url":"https://github.com/NixOS/nixpkgs/security/advisories/GHSA-58m4-5wg3-5g5v"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:108199207f5f20bc025b0f6c8d4a2b0de1e6471a4f7aae357d534677c927c552 · sha256:5f4a45e03d20db74… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.