VendorsNim-langnimany version
Vulnerabilities

Nim-lang Nim any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2020-15692
In Nim 1.2.4, the standard library browsers mishandles the URL argument to browsers.openDefaultBrowser. This argument can be a local file path that will be opened in the default explorer. An attacker can pass one argument to the underlying open command to execute arbitrary registered system commands.
Published 2020-08-14 · Modified
10.0EPSS 0.042
CVE-2020-15690
In Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains a newline character.
Published 2021-01-30 · Modified
9.8EPSS 0.032
CVE-2021-21372
Nimble arbitrary code execution for specially crafted package metadata
Published 2021-03-26 · Modified
8.8EPSS 0.036
CVE-2021-21374
Nimble fails to validate certificates due to insecure httpClient defaults
Published 2021-03-26 · Modified
8.1EPSS 0.010
CVE-2020-15694
In Nim 1.2.4, the standard library httpClient fails to properly validate the server response. For example, httpClient.get().contentLength() does not raise any error if a malicious server provides a negative Content-Length.
Published 2020-08-14 · Modified
7.5EPSS 0.023
CVE-2021-21373
Nimble falls back to insecure http url when fetching packages
Published 2021-03-26 · Modified
7.5EPSS 0.012
CVE-2021-29495
Nim stdlib httpClient does not validate peer certificates by default
Published 2021-05-07 · Modified
7.5EPSS 0.005
CVE-2020-15693
In Nim 1.2.4, the standard library httpClient is vulnerable to a CR-LF injection in the target URL. An injection is possible if the attacker controls any part of the URL provided in a call (such as httpClient.get or httpClient.post), the User-Agent header value, or custom HTTP header names or values.
Published 2020-08-14 · Modified
6.5EPSS 0.020
CVE-2021-46872
An issue was discovered in Nim before 1.6.2. The RST module of the Nim language stdlib, as used in NimForum and other products, permits the javascript: URI scheme and thus can lead to XSS in some applications. (Nim versions 1.6.2 and later are fixed; there may be backports of the fix to some earlier versions. NimForum 2.2.0 is fixed.)
Published 2023-01-13 · Modified
6.1EPSS 0.005