216.73.216.6

CVE-2025-32800

· Published 16/06/2025 21:15 · Modified 16/06/2025 21:15

Labels: CVE-2025-32800 2025-06-16CVE-2025-32800CWE-1357[email protected]

Essential information

Published
16/06/2025 21:15
Modified
16/06/2025 21:15
Author
Creator
CVSS
7.2 HIGH (v3) 7.2 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Conda-build contains commands and tools to build conda packages. Prior to version 25.3.0, the pyproject.toml lists conda-index as a Python dependency. This package is not published in PyPI. An attacker could claim this namespace and upload arbitrary (malicious) code to the package, and then exploit pip install commands by injecting the malicious dependency in the solve. This issue has been fixed in version 25.3.0. A workaround involves using --no-deps for pip install-ing the project from the repository.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
anaconda / conda-build cpe:2.3:a:anaconda:conda-build:<25.3.0:*:*:*:*:*:*:*

References