CVE Explorer
CVE-2026-23838
Tandoor Recipes is a recipe manager than can be installed with the Nix package manager. Starting in version 23.05 and prior to version 26.05, when using the default configuration of Tandoor Recipes, specifically using SQLite and default `MEDIA_ROOT`, the full database file may be externally accessible, potentially on the Internet. The root cause is that the NixOS module configures the working directory of Tandoor Recipes, as well as the value of `MEDIA_ROOT`, to be `/var/lib/tandoor-recipes`. Th
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"nixpkgs","vendor":"NixOS","versions":[{"status":"affected","version":">= 23.05, < 26.05"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:633fcb9b2f6819caebc56a9607d3d17ad4d4e6d1375b3dad0de8951c06ce1ae3 · sha256:9582dcb8a3499462… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.7,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:633fcb9b2f6819caebc56a9607d3d17ad4d4e6d1375b3dad0de8951c06ce1ae3 · sha256:9582dcb8a3499462… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-538","description":"CWE-538: Insertion of Sensitive Information into Externally-Accessible File or Directory","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:633fcb9b2f6819caebc56a9607d3d17ad4d4e6d1375b3dad0de8951c06ce1ae3 · sha256:9582dcb8a3499462… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://github.com/NixOS/nixpkgs/issues/338339","tags":["x_refsource_MISC"],"url":"https://github.com/NixOS/nixpkgs/issues/338339"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:633fcb9b2f6819caebc56a9607d3d17ad4d4e6d1375b3dad0de8951c06ce1ae3 · sha256:9582dcb8a3499462… · /containers/cna/references/1
{"name":"https://github.com/NixOS/nixpkgs/pull/427845","tags":["x_refsource_MISC"],"url":"https://github.com/NixOS/nixpkgs/pull/427845"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:633fcb9b2f6819caebc56a9607d3d17ad4d4e6d1375b3dad0de8951c06ce1ae3 · sha256:9582dcb8a3499462… · /containers/cna/references/2
{"name":"https://github.com/NixOS/nixpkgs/pull/481140","tags":["x_refsource_MISC"],"url":"https://github.com/NixOS/nixpkgs/pull/481140"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:633fcb9b2f6819caebc56a9607d3d17ad4d4e6d1375b3dad0de8951c06ce1ae3 · sha256:9582dcb8a3499462… · /containers/cna/references/3
{"name":"https://github.com/NixOS/nixpkgs/security/advisories/GHSA-g8w3-p77x-mmxh","tags":["x_refsource_CONFIRM"],"url":"https://github.com/NixOS/nixpkgs/security/advisories/GHSA-g8w3-p77x-mmxh"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:633fcb9b2f6819caebc56a9607d3d17ad4d4e6d1375b3dad0de8951c06ce1ae3 · sha256:9582dcb8a3499462… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.