CVE-2025-32800
Conda-build contains commands and tools to build conda packages. Prior to version 25.3.0, the pyproject.toml lists conda-index as a Python dependency. This package is not published in PyPI. An attacker could claim this namespace and upload arbitrary (malicious) code to the package, and then exploit pip install commands by injecting the malicious dependency in the solve. This issue has been fixed in version 25.3.0. A workaround involves using --no-deps for pip install-ing the project from the repository.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.2
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U
- EPSS probability
- 0.60%
- CWE
- CWE-1357
- Published
- 2025-06-16
- Last modified
- 2026-03-13
Affected products
- conda conda-build
Weakness type
Related vulnerabilities
- CVE-2026-67275 — Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently...
- CVE-2026-75569 — Mce-operator-bundle: all github actions pinned by mutable tag, not commit sha
- CVE-2026-66783 — Submariner-operator: release workflow consumes same-org composite action via mutable @devel branch ref
- CVE-2026-47619 — NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause...
- CVE-2024-26024 — SUBNET Substation Server Reliance on Insufficiently Trustworthy Component
- CVE-2024-28042 — SUBNET PowerSYSTEM Center Reliance on Insufficiently Trustworthy Component
- CVE-2024-3313 — SUBNET PowerSYSTEM Server and Substation Server Reliance on Insufficiently Trustworthy Component