NuGet.PackageManagement
NuGet Package Management functionality for Visual Studio installation flow.
Activity
- Latest release
- 4mo ago
- Total releases
- 78
- Cadence
- ~daily
- Last 12 months
- 12
Details
- License
- Apache-2.0
- First release
- Sep 16, 2015
| Version | Released | |
|---|---|---|
7.6.0
minor
|
7.6.0
minor
Dependencies (4)
|
|
7.0.3
patch
|
7.0.3
patch
Dependencies (4)
|
|
5.11.7
patch
|
5.11.7
patch
Dependencies (4)
|
|
7.3.1
patch
|
7.3.1
patch
Dependencies (4)
|
|
6.14.3
patch
|
6.14.3
patch
Dependencies (5)
|
|
6.11.2
patch
|
6.11.2
patch
Dependencies (5)
|
|
6.12.5
patch
|
6.12.5
patch
Dependencies (5)
|
|
6.8.2
patch
|
6.8.2
patch
Dependencies (5)
|
|
4.9.7+2f95c369aa79225d4fbc752f4ec5063d71cdfd08
patch
1 CVE
CVE-2023-29337
GHSA-6qmf-mmc7-6c2p
Jun 14, 2023
NuGet Client Remote Code Execution Vulnerability
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
DescriptionMicrosoft is releasing this security advisory to provide information about a vulnerability in .NET and NuGet on Linux. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exists in .NET 6.0, .NET 7.0 and NuGet(nuget.exe, NuGet.Protocol, NuGet.Common, NuGet.CommandLine, NuGet.Commands, Microsoft.Build.NuGetSdkResolver, NuGet.PackageManagement) where a potential race condition that can lead to a symlink attack on Linux. Non-Linux platforms are not affected. Affected softwareThis issue only affects Linux systems. NuGet & NuGet Packages
.NET SDK(s)
PatchesTo fix the issue, please install the latest version of .NET 6.0 or .NET 7.0 and NuGet (NuGet.exe, NuGet.Protocol, NuGet.Common, NuGet.CommandLine, NuGet.Commands, NuGet.PackageManagement versions). If you have installed one or more .NET SDKs through Visual Studio, Visual Studio will prompt you to update Visual Studio, which will also update your .NET SDKs.
Other detailsAnnouncement for this issue can be found at https://github.com/NuGet/Announcements/issues/69 MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29337 Affected versions
6.0.0
6.0.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
6.5.0
6.6.0
4.6.0
4.6.1
+ 14 more Show less
4.6.2
4.6.3
4.6.4
4.7.0-preview1-4986
5.10.0
5.11.0
5.11.2
5.11.3
5.7.1
5.7.2
5.9.0
5.9.1
5.9.2
5.9.3
Fixed in
5.11.5
6.0.5
6.2.4
6.3.3
6.4.2
6.5.1
6.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
4.9.7+2f95c369aa79225d4fbc752f4ec5063d71cdfd08
patch
Dependencies (3)
|
|
7.3.0
minor
|
7.3.0
minor
Dependencies (4)
|
|
7.0.1
patch
|
7.0.1
patch
Dependencies (4)
|
|
7.0.0
major
|
7.0.0
major
Dependencies (4)
|
|
6.14.0
minor
|
6.14.0
minor
Dependencies (5)
|
|
6.12.4
patch
|
6.12.4
patch
Dependencies (5)
|
|
6.13.2
patch
|
6.13.2
patch
Dependencies (5)
|
|
6.13.1
minor
|
6.13.1
minor
Dependencies (5)
|
|
6.12.0
minor
|
6.12.0
minor
Dependencies (5)
|
|
6.12.1
patch
|
6.12.1
patch
Dependencies (5)
|
|
6.11.1
patch
|
6.11.1
patch
Dependencies (5)
|
|
6.11.0
minor
|
6.11.0
minor
Dependencies (5)
|
|
6.10.2
patch
|
6.10.2
patch
Dependencies (5)
|
|
6.10.1
patch
|
6.10.1
patch
Dependencies (5)
|
|
6.11.0-preview.2
pre
|
6.11.0-preview.2
pre
Dependencies (5)
|
|
6.10.0
minor
|
6.10.0
minor
Dependencies (5)
|
|
6.7.1
patch
|
6.7.1
patch
Dependencies (5)
|
|
6.0.6
patch
|
6.0.6
patch
Dependencies (5)
|
|
5.11.6
patch
|
5.11.6
patch
Dependencies (4)
|
|
6.3.4
patch
|
6.3.4
patch
Dependencies (5)
|
|
6.4.3
patch
|
6.4.3
patch
Dependencies (5)
|
|
6.6.2
patch
|
6.6.2
patch
Dependencies (5)
|
|
6.8.1
patch
|
6.8.1
patch
Dependencies (5)
|
|
6.9.1
minor
|
6.9.1
minor
Dependencies (5)
|
|
6.8.0
minor
|
6.8.0
minor
Dependencies (5)
|
|
6.7.0
minor
|
6.7.0
minor
Dependencies (5)
|
|
5.11.5
patch
|
5.11.5
patch
Dependencies (4)
|
|
6.3.3
patch
|
6.3.3
patch
Dependencies (5)
|
|
6.2.4
patch
|
6.2.4
patch
Dependencies (5)
|
|
6.0.5
patch
|
6.0.5
patch
Dependencies (5)
|
|
6.5.1
patch
|
6.5.1
patch
Dependencies (5)
|
|
6.4.2
patch
|
6.4.2
patch
Dependencies (5)
|
|
6.6.1
patch
|
6.6.1
patch
Dependencies (5)
|
|
6.6.0
minor
1 CVE
CVE-2023-29337
GHSA-6qmf-mmc7-6c2p
Jun 14, 2023
NuGet Client Remote Code Execution Vulnerability
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
DescriptionMicrosoft is releasing this security advisory to provide information about a vulnerability in .NET and NuGet on Linux. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exists in .NET 6.0, .NET 7.0 and NuGet(nuget.exe, NuGet.Protocol, NuGet.Common, NuGet.CommandLine, NuGet.Commands, Microsoft.Build.NuGetSdkResolver, NuGet.PackageManagement) where a potential race condition that can lead to a symlink attack on Linux. Non-Linux platforms are not affected. Affected softwareThis issue only affects Linux systems. NuGet & NuGet Packages
.NET SDK(s)
PatchesTo fix the issue, please install the latest version of .NET 6.0 or .NET 7.0 and NuGet (NuGet.exe, NuGet.Protocol, NuGet.Common, NuGet.CommandLine, NuGet.Commands, NuGet.PackageManagement versions). If you have installed one or more .NET SDKs through Visual Studio, Visual Studio will prompt you to update Visual Studio, which will also update your .NET SDKs.
Other detailsAnnouncement for this issue can be found at https://github.com/NuGet/Announcements/issues/69 MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29337 Affected versions
6.0.0
6.0.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
6.5.0
6.6.0
4.6.0
4.6.1
+ 14 more Show less
4.6.2
4.6.3
4.6.4
4.7.0-preview1-4986
5.10.0
5.11.0
5.11.2
5.11.3
5.7.1
5.7.2
5.9.0
5.9.1
5.9.2
5.9.3
Fixed in
5.11.5
6.0.5
6.2.4
6.3.3
6.4.2
6.5.1
6.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
6.6.0
minor
Dependencies (5)
|
|
6.6.0-preview.3
pre
|
6.6.0-preview.3
pre
Dependencies (5)
|
|
6.5.0
minor
1 CVE
CVE-2023-29337
GHSA-6qmf-mmc7-6c2p
Jun 14, 2023
NuGet Client Remote Code Execution Vulnerability
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
DescriptionMicrosoft is releasing this security advisory to provide information about a vulnerability in .NET and NuGet on Linux. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exists in .NET 6.0, .NET 7.0 and NuGet(nuget.exe, NuGet.Protocol, NuGet.Common, NuGet.CommandLine, NuGet.Commands, Microsoft.Build.NuGetSdkResolver, NuGet.PackageManagement) where a potential race condition that can lead to a symlink attack on Linux. Non-Linux platforms are not affected. Affected softwareThis issue only affects Linux systems. NuGet & NuGet Packages
.NET SDK(s)
PatchesTo fix the issue, please install the latest version of .NET 6.0 or .NET 7.0 and NuGet (NuGet.exe, NuGet.Protocol, NuGet.Common, NuGet.CommandLine, NuGet.Commands, NuGet.PackageManagement versions). If you have installed one or more .NET SDKs through Visual Studio, Visual Studio will prompt you to update Visual Studio, which will also update your .NET SDKs.
Other detailsAnnouncement for this issue can be found at https://github.com/NuGet/Announcements/issues/69 MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29337 Affected versions
6.0.0
6.0.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
6.5.0
6.6.0
4.6.0
4.6.1
+ 14 more Show less
4.6.2
4.6.3
4.6.4
4.7.0-preview1-4986
5.10.0
5.11.0
5.11.2
5.11.3
5.7.1
5.7.2
5.9.0
5.9.1
5.9.2
5.9.3
Fixed in
5.11.5
6.0.5
6.2.4
6.3.3
6.4.2
6.5.1
6.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
6.5.0
minor
Dependencies (5)
|
|
6.4.0
minor
1 CVE
CVE-2023-29337
GHSA-6qmf-mmc7-6c2p
Jun 14, 2023
NuGet Client Remote Code Execution Vulnerability
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
DescriptionMicrosoft is releasing this security advisory to provide information about a vulnerability in .NET and NuGet on Linux. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exists in .NET 6.0, .NET 7.0 and NuGet(nuget.exe, NuGet.Protocol, NuGet.Common, NuGet.CommandLine, NuGet.Commands, Microsoft.Build.NuGetSdkResolver, NuGet.PackageManagement) where a potential race condition that can lead to a symlink attack on Linux. Non-Linux platforms are not affected. Affected softwareThis issue only affects Linux systems. NuGet & NuGet Packages
.NET SDK(s)
PatchesTo fix the issue, please install the latest version of .NET 6.0 or .NET 7.0 and NuGet (NuGet.exe, NuGet.Protocol, NuGet.Common, NuGet.CommandLine, NuGet.Commands, NuGet.PackageManagement versions). If you have installed one or more .NET SDKs through Visual Studio, Visual Studio will prompt you to update Visual Studio, which will also update your .NET SDKs.
Other detailsAnnouncement for this issue can be found at https://github.com/NuGet/Announcements/issues/69 MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29337 Affected versions
6.0.0
6.0.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
6.5.0
6.6.0
4.6.0
4.6.1
+ 14 more Show less
4.6.2
4.6.3
4.6.4
4.7.0-preview1-4986
5.10.0
5.11.0
5.11.2
5.11.3
5.7.1
5.7.2
5.9.0
5.9.1
5.9.2
5.9.3
Fixed in
5.11.5
6.0.5
6.2.4
6.3.3
6.4.2
6.5.1
6.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
6.4.0
minor
Dependencies (5)
|
|
6.3.1
minor
1 CVE
CVE-2023-29337
GHSA-6qmf-mmc7-6c2p
Jun 14, 2023
NuGet Client Remote Code Execution Vulnerability
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
DescriptionMicrosoft is releasing this security advisory to provide information about a vulnerability in .NET and NuGet on Linux. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exists in .NET 6.0, .NET 7.0 and NuGet(nuget.exe, NuGet.Protocol, NuGet.Common, NuGet.CommandLine, NuGet.Commands, Microsoft.Build.NuGetSdkResolver, NuGet.PackageManagement) where a potential race condition that can lead to a symlink attack on Linux. Non-Linux platforms are not affected. Affected softwareThis issue only affects Linux systems. NuGet & NuGet Packages
.NET SDK(s)
PatchesTo fix the issue, please install the latest version of .NET 6.0 or .NET 7.0 and NuGet (NuGet.exe, NuGet.Protocol, NuGet.Common, NuGet.CommandLine, NuGet.Commands, NuGet.PackageManagement versions). If you have installed one or more .NET SDKs through Visual Studio, Visual Studio will prompt you to update Visual Studio, which will also update your .NET SDKs.
Other detailsAnnouncement for this issue can be found at https://github.com/NuGet/Announcements/issues/69 MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29337 Affected versions
6.0.0
6.0.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
6.5.0
6.6.0
4.6.0
4.6.1
+ 14 more Show less
4.6.2
4.6.3
4.6.4
4.7.0-preview1-4986
5.10.0
5.11.0
5.11.2
5.11.3
5.7.1
5.7.2
5.9.0
5.9.1
5.9.2
5.9.3
Fixed in
5.11.5
6.0.5
6.2.4
6.3.3
6.4.2
6.5.1
6.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
6.3.1
minor
Dependencies (5)
|
|
6.0.3-rc.1
pre
1 CVE
CVE-2023-29337
GHSA-6qmf-mmc7-6c2p
Jun 14, 2023
NuGet Client Remote Code Execution Vulnerability
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
DescriptionMicrosoft is releasing this security advisory to provide information about a vulnerability in .NET and NuGet on Linux. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exists in .NET 6.0, .NET 7.0 and NuGet(nuget.exe, NuGet.Protocol, NuGet.Common, NuGet.CommandLine, NuGet.Commands, Microsoft.Build.NuGetSdkResolver, NuGet.PackageManagement) where a potential race condition that can lead to a symlink attack on Linux. Non-Linux platforms are not affected. Affected softwareThis issue only affects Linux systems. NuGet & NuGet Packages
.NET SDK(s)
PatchesTo fix the issue, please install the latest version of .NET 6.0 or .NET 7.0 and NuGet (NuGet.exe, NuGet.Protocol, NuGet.Common, NuGet.CommandLine, NuGet.Commands, NuGet.PackageManagement versions). If you have installed one or more .NET SDKs through Visual Studio, Visual Studio will prompt you to update Visual Studio, which will also update your .NET SDKs.
Other detailsAnnouncement for this issue can be found at https://github.com/NuGet/Announcements/issues/69 MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29337 Affected versions
6.0.0
6.0.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
6.5.0
6.6.0
4.6.0
4.6.1
+ 14 more Show less
4.6.2
4.6.3
4.6.4
4.7.0-preview1-4986
5.10.0
5.11.0
5.11.2
5.11.3
5.7.1
5.7.2
5.9.0
5.9.1
5.9.2
5.9.3
Fixed in
5.11.5
6.0.5
6.2.4
6.3.3
6.4.2
6.5.1
6.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
6.0.3-rc.1
pre
Dependencies (5)
|
|
5.7.3-rtm.5
pre
1 CVE
CVE-2023-29337
GHSA-6qmf-mmc7-6c2p
Jun 14, 2023
NuGet Client Remote Code Execution Vulnerability
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
DescriptionMicrosoft is releasing this security advisory to provide information about a vulnerability in .NET and NuGet on Linux. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exists in .NET 6.0, .NET 7.0 and NuGet(nuget.exe, NuGet.Protocol, NuGet.Common, NuGet.CommandLine, NuGet.Commands, Microsoft.Build.NuGetSdkResolver, NuGet.PackageManagement) where a potential race condition that can lead to a symlink attack on Linux. Non-Linux platforms are not affected. Affected softwareThis issue only affects Linux systems. NuGet & NuGet Packages
.NET SDK(s)
PatchesTo fix the issue, please install the latest version of .NET 6.0 or .NET 7.0 and NuGet (NuGet.exe, NuGet.Protocol, NuGet.Common, NuGet.CommandLine, NuGet.Commands, NuGet.PackageManagement versions). If you have installed one or more .NET SDKs through Visual Studio, Visual Studio will prompt you to update Visual Studio, which will also update your .NET SDKs.
Other detailsAnnouncement for this issue can be found at https://github.com/NuGet/Announcements/issues/69 MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29337 Affected versions
6.0.0
6.0.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
6.5.0
6.6.0
4.6.0
4.6.1
+ 14 more Show less
4.6.2
4.6.3
4.6.4
4.7.0-preview1-4986
5.10.0
5.11.0
5.11.2
5.11.3
5.7.1
5.7.2
5.9.0
5.9.1
5.9.2
5.9.3
Fixed in
5.11.5
6.0.5
6.2.4
6.3.3
6.4.2
6.5.1
6.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.7.3-rtm.5
pre
Dependencies (3)
|
|
6.2.2
minor
1 CVE
CVE-2023-29337
GHSA-6qmf-mmc7-6c2p
Jun 14, 2023
NuGet Client Remote Code Execution Vulnerability
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
DescriptionMicrosoft is releasing this security advisory to provide information about a vulnerability in .NET and NuGet on Linux. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exists in .NET 6.0, .NET 7.0 and NuGet(nuget.exe, NuGet.Protocol, NuGet.Common, NuGet.CommandLine, NuGet.Commands, Microsoft.Build.NuGetSdkResolver, NuGet.PackageManagement) where a potential race condition that can lead to a symlink attack on Linux. Non-Linux platforms are not affected. Affected softwareThis issue only affects Linux systems. NuGet & NuGet Packages
.NET SDK(s)
PatchesTo fix the issue, please install the latest version of .NET 6.0 or .NET 7.0 and NuGet (NuGet.exe, NuGet.Protocol, NuGet.Common, NuGet.CommandLine, NuGet.Commands, NuGet.PackageManagement versions). If you have installed one or more .NET SDKs through Visual Studio, Visual Studio will prompt you to update Visual Studio, which will also update your .NET SDKs.
Other detailsAnnouncement for this issue can be found at https://github.com/NuGet/Announcements/issues/69 MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29337 Affected versions
6.0.0
6.0.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
6.5.0
6.6.0
4.6.0
4.6.1
+ 14 more Show less
4.6.2
4.6.3
4.6.4
4.7.0-preview1-4986
5.10.0
5.11.0
5.11.2
5.11.3
5.7.1
5.7.2
5.9.0
5.9.1
5.9.2
5.9.3
Fixed in
5.11.5
6.0.5
6.2.4
6.3.3
6.4.2
6.5.1
6.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
6.2.2
minor
Dependencies (5)
|
|
5.11.3
minor
1 CVE
CVE-2023-29337
GHSA-6qmf-mmc7-6c2p
Jun 14, 2023
NuGet Client Remote Code Execution Vulnerability
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
DescriptionMicrosoft is releasing this security advisory to provide information about a vulnerability in .NET and NuGet on Linux. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exists in .NET 6.0, .NET 7.0 and NuGet(nuget.exe, NuGet.Protocol, NuGet.Common, NuGet.CommandLine, NuGet.Commands, Microsoft.Build.NuGetSdkResolver, NuGet.PackageManagement) where a potential race condition that can lead to a symlink attack on Linux. Non-Linux platforms are not affected. Affected softwareThis issue only affects Linux systems. NuGet & NuGet Packages
.NET SDK(s)
PatchesTo fix the issue, please install the latest version of .NET 6.0 or .NET 7.0 and NuGet (NuGet.exe, NuGet.Protocol, NuGet.Common, NuGet.CommandLine, NuGet.Commands, NuGet.PackageManagement versions). If you have installed one or more .NET SDKs through Visual Studio, Visual Studio will prompt you to update Visual Studio, which will also update your .NET SDKs.
Other detailsAnnouncement for this issue can be found at https://github.com/NuGet/Announcements/issues/69 MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29337 Affected versions
6.0.0
6.0.2
6.2.0
6.2.1
6.2.2
6.3.0
6.3.1
6.4.0
6.5.0
6.6.0
4.6.0
4.6.1
+ 14 more Show less
4.6.2
4.6.3
4.6.4
4.7.0-preview1-4986
5.10.0
5.11.0
5.11.2
5.11.3
5.7.1
5.7.2
5.9.0
5.9.1
5.9.2
5.9.3
Fixed in
5.11.5
6.0.5
6.2.4
6.3.3
6.4.2
6.5.1
6.6.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.11.3
minor
Dependencies (4)
|