conda is vulnerable to Path Traversal
88
High Risk
parse_entry_point_def only rsplits and strips a noarch Python entry-point definition, then CreatePythonEntryPointAction interpolates the resulting command into {BIN_DIRECTORY}/{command} with a no-op verify(). A malicious noarch:python package can put .., /, \, or an absolute path in info/link.json so conda writes an executable wrapper outside the prefix or overwrites an in-prefix entry point such as pip. That write happens on the default path of conda install and related transactions, so a later invocation of the overwritten command runs attacker-controlled Python. The fix rejects entry-point names that are not a simple file name before generating the wrapper scripts.
You are affected if you are using a version that falls within the vulnerable range and you install noarch:python packages from channels you do not fully trust.
conda is vulnerable to Path Traversal in versions 0.0.1 - 26.5.1.
Upgrade the conda library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.