PT-2025-25610 · Unknown · Conda Constructor

Stamparm

·

Published

2025-06-17

·

Updated

2025-06-17

·

CVE-2025-49823

CVSS v3.1

0.0

None

VectorAV:P/AC:H/PR:H/UI:R/S:C/C:N/I:N/A:N
Name of the Vulnerable Software and Affected Versions Conda Constructor versions prior to 3.11.3
Description The issue concerns the Conda Constructor, a tool for creating installers for conda packages. Prior to version 3.11.3, the shell installer scripts process the installation prefix using an eval statement, which executes unsanitized user input as shell code. This allows an attacker to inject arbitrary commands through a malicious path during installation, although it requires explicit user action. The script runs with user privileges, not root.
Recommendations For versions prior to 3.11.3, update to version 3.11.3 to resolve the issue. As a temporary workaround, consider avoiding the use of the shell installer scripts until the update is applied.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-49823
GHSA-44Q9-RG2Q-5G99

Affected Products

Conda Constructor