From de9575c19f58a24a38dcdc63dac77a9a513fe880 Mon Sep 17 00:00:00 2001 From: ppom <38916722+ppom0@users.noreply.github.com> Date: Sat, 23 May 2026 12:00:00 +0200 Subject: [PATCH] peertube: fix security issue This issue doesn't have a CVE yet. For context, see: - https://github.com/Chocobozzz/PeerTube/releases/ - https://github.com/Chocobozzz/PeerTube/issues/7622 Not-cherry-picked-because: v7 on stable doesn't have a patch release, but v8 on master has one --- pkgs/by-name/pe/peertube/package.nix | 5 ++++ .../pe/peertube/sql-injection-fix.patch | 27 +++++++++++++++++++ 2 files changed, 32 insertions(+) create mode 100644 pkgs/by-name/pe/peertube/sql-injection-fix.patch diff --git a/pkgs/by-name/pe/peertube/package.nix b/pkgs/by-name/pe/peertube/package.nix index 58c4142829c6..f4e8ca925725 100644 --- a/pkgs/by-name/pe/peertube/package.nix +++ b/pkgs/by-name/pe/peertube/package.nix @@ -56,6 +56,11 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-WbZFOOvX6WzKB9tszxJl6z+V6cDBH6Y2SjoxF17WvUo="; }; + patches = [ + # https://github.com/Chocobozzz/PeerTube/issues/7622 + ./sql-injection-fix.patch + ]; + yarnOfflineCacheServer = fetchYarnDeps { yarnLock = "${finalAttrs.src}/yarn.lock"; hash = "sha256-T1stKz8+1ghQBJB8kujwcqmygMdoswjFBL/QWAHSis0="; diff --git a/pkgs/by-name/pe/peertube/sql-injection-fix.patch b/pkgs/by-name/pe/peertube/sql-injection-fix.patch new file mode 100644 index 000000000000..2517a5d8d04f --- /dev/null +++ b/pkgs/by-name/pe/peertube/sql-injection-fix.patch @@ -0,0 +1,27 @@ +diff --git i/server/core/models/actor/actor-follow.ts w/server/core/models/actor/actor-follow.ts +index 6852a0b3a..807ebcfdb 100644 +--- i/server/core/models/actor/actor-follow.ts ++++ w/server/core/models/actor/actor-follow.ts +@@ -633,20 +633,8 @@ export class ActorFollowModel extends SequelizeModel { + } + } + +- static updateScore (inboxUrl: string, value: number, t?: Transaction) { +- const query = `UPDATE "actorFollow" SET "score" = LEAST("score" + ${value}, ${ACTOR_FOLLOW_SCORE.MAX}) ` + +- 'WHERE id IN (' + +- 'SELECT "actorFollow"."id" FROM "actorFollow" ' + +- 'INNER JOIN "actor" ON "actor"."id" = "actorFollow"."actorId" ' + +- `WHERE "actor"."inboxUrl" = '${inboxUrl}' OR "actor"."sharedInboxUrl" = '${inboxUrl}'` + +- ')' +- +- const options = { +- type: QueryTypes.BULKUPDATE, +- transaction: t +- } +- +- return ActorFollowModel.sequelize.query(query, options) ++ static updateScore (_inboxUrl: string, _value: number, _t?: Transaction) { ++ return + } + + static async updateScoreByFollowingServers (serverIds: number[], value: number, t?: Transaction) {