PT-2026-96140 · Conda · Conda

CVE-2026-53940

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Conda versions prior to 26.5.2
Description The parse entry point def function in conda/common/path/python.py accepts unvalidated entry-point commands from the info/link.json metadata of noarch:python packages. The CreatePythonEntryPointAction in conda/core/path actions.py interpolates this command into target short path, and PrefixPathAction.target full path joins it to the installation prefix without verifying if the result remains within the intended bin or Scripts directory. Subsequently, create python entry point in conda/gateways/disk/create.py writes an executable wrapper to that path. A malicious package can utilize path separators, traversal segments, or absolute command paths to write files outside the prefix or overwrite existing entry points during installation and environment transactions. This can lead to the execution of attacker-controlled Python code with the privileges of the installing user.
Recommendations Update to version 26.5.2.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53940
GHSA-9M8M-C4J3-RJ2C

Affected Products

Conda