PT-2026-50794 · Unknown · Conda-Smithy

·

CVE-2026-46699

·

Published

2026-06-18

·

Updated

2026-06-23

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions conda-smithy versions prior to 3.61.0
Description conda-smithy is a tool that combines a conda recipe with configurations to build using freely hosted CI services into a single repository. A flaw in the conda-forge automated webservices allows unintended write access to feedstock repositories via GitHub username takeover. This occurs because mutable GitHub usernames are used as identifiers for repository invitation routing instead of stable, immutable GitHub user IDs.
Recommendations Update to version 3.61.0.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46699
GHSA-G95Q-3CMJ-FVH8

Affected Products

Conda-Smithy