Several security issues were discovered in Guix: https://guix.gnu.org/en/blog/2026/guix-substitute-pull-vulnerabilities/ "Several security issues (CVE IDs pending) have been identified in guix substitute, a helper utility invoked by guix-daemon, which enable a variety of harmful activities including remote privilege escalation to the build daemon user, remote store corruption, and potentially local disclosure of sensitive files accessible to the build daemon user." There is some existing work to mitigate this by backporting upstream patches: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1148812&pow_referer=#10 "I managed to backport patches on top of Guix 1.5.0. They are in the guix-1.5.0-backports branch in https://git.sr.ht/~gnutoo/guix." But I have been unable to successfully use guix substitutes with those patches applied. Will try to get more details on that at some point. live well, vagrant