{"id":"CVE-2026-25740","summary":"Privilege escalation to the `CAP_NET_RAW` capability via the `programs.captive-browser` NixOS module","details":"captive browser, a dedicated Chrome instance to log into captive portals without messing with DNS settings. In 25.05 and earlier, when programs.captive-browser is enabled, any user of the system can run arbitrary commands with the CAP_NET_RAW capability (binding to privileged ports, spoofing localhost traffic from privileged services...). This vulnerability is fixed in 25.11 and 26.05.","aliases":["GHSA-wc3r-c66x-8xmc"],"modified":"2026-08-12T03:51:15.477656323Z","published":"2026-02-09T20:17:16.777Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-250"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25740.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25740.json"},{"type":"ADVISORY","url":"https://github.com/NixOS/nixpkgs/security/advisories/GHSA-wc3r-c66x-8xmc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25740"},{"type":"FIX","url":"https://github.com/NixOS/nixpkgs/pull/487775"},{"type":"FIX","url":"https://github.com/NixOS/nixpkgs/pull/487779"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nixos/nixpkgs","events":[{"introduced":"0"},{"last_affected":"c46290747b2aaf090f48a478270feb858837bf11"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"last_affected":"25.05"}]}}],"versions":["25.05-pre","24.11-pre","24.05-pre","23.11-beta","23.11-pre","23.05-pre","21.11-pre","18.09-beta","18.03-beta","v208","v206","v192","15.09-beta","0.14","0.13","0.4","0.3","0.2","0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25740.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N"}]}