CVE Feed

    Dashboard / CVE / CVE-2025-32799

    CVE-2025-32799

    Conda-build contains commands and tools to build conda packages. Prior to version 25.4.0, the conda-build processing logic is vulnerable to path traversal (Tarslip) attacks due to improper sanitization of tar entry paths. Attackers can craft tar archives containing entries with directory traversal sequences to write files outside the intended extraction directory. This could lead to arbitrary file overwrites, privilege escalation, or code execution if sensitive locations are targeted. This issue has been patched in version 25.4.0.

    Published:Jun 16, 2025
    Last Modified:Jul 2, 2025
    EPS:Jun 16, 2025
    EPSS Score:0.00445
    CVSS Score:9.8

    Affected Products

    Vendor
    Anaconda
    Product
    Conda-build

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High