A vulnerability in the Guix package manager allows remote code execution.
Vulnerabilities (CVE not assigned) have been identified in the Guix package manager in the implementation of the internal "guix substitute" command, which is automatically invoked by the guix-daemon background process during package installations. The command is used to download pre-built binary packages from external servers and verify their integrity using a digital signature. The most severe vulnerability allows remote code execution on a user's system […]
