PT-2026-96140 · Conda · Conda
CVE-2026-53940
·
Published
2026-09-21
·
Updated
2026-09-21
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Conda versions prior to 26.5.2
Description
The
parse entry point def function in conda/common/path/python.py accepts unvalidated entry-point commands from the info/link.json metadata of noarch:python packages. The CreatePythonEntryPointAction in conda/core/path actions.py interpolates this command into target short path, and PrefixPathAction.target full path joins it to the installation prefix without verifying if the result remains within the intended bin or Scripts directory. Subsequently, create python entry point in conda/gateways/disk/create.py writes an executable wrapper to that path. A malicious package can utilize path separators, traversal segments, or absolute command paths to write files outside the prefix or overwrite existing entry points during installation and environment transactions. This can lead to the execution of attacker-controlled Python code with the privileges of the installing user.Recommendations
Update to version 26.5.2.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Conda