Vulnerabilities
Products Security index
Vulnerabilities
CVE-2026-23528
Dask distributed Vulnerable to Remote Code Execution via Jupyter Proxy and Dashboard
CVE-2024-46060
Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This allows a local low-privileged user to inject arbitrary commands, leading to code execution as the root user.
CVE-2024-46062
Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This flaw allows a local low-privileged user to inject arbitrary commands, leading to code execution as the root user.
CVE-2025-32800
Conda-build vulnerable to supply chain attack vector due to pyproject.toml referring to dependencies not present in PyPI
CVE-2025-32799
Conda-build Vulnerable to Path Traversal via Malicious Tar File
