Intel

AIKIDO-2026-737163

conda is vulnerable to Path Traversal

Path TraversalCVE-2026-53940 Published 5 days ago

88

High Risk

This Affects:

PYTHONconda
0.0.1 - 26.5.1
Fixed in 26.5.2
Are you affected? Scan for Free

TL;DR

parse_entry_point_def only rsplits and strips a noarch Python entry-point definition, then CreatePythonEntryPointAction interpolates the resulting command into {BIN_DIRECTORY}/{command} with a no-op verify(). A malicious noarch:python package can put .., /, \, or an absolute path in info/link.json so conda writes an executable wrapper outside the prefix or overwrites an in-prefix entry point such as pip. That write happens on the default path of conda install and related transactions, so a later invocation of the overwritten command runs attacker-controlled Python. The fix rejects entry-point names that are not a simple file name before generating the wrapper scripts.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you install noarch:python packages from channels you do not fully trust.

Background info

conda is vulnerable to Path Traversal in versions 0.0.1 - 26.5.1.

How to fix this

Upgrade the conda library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform