Impact
Conda’s package installer allowed unvalidated entry‑point commands from noarch:python packages. The command was written directly to a path derived from the installation prefix without verifying that the result stayed under the intended bin or Scripts directory. A malicious package could use path separators, traversal segments, or an absolute path to create or overwrite files outside the prefix or to replace an existing entry point. The resulting write would execute attacker‑controlled Python code with the installing user’s privileges, providing a vector for arbitrary code execution.
Affected Systems
Any system running Conda prior to version 26.5.2 is affected. The vulnerability originates in conda/common/path/python.py, conda/core/path_actions.py, and conda/gateways/disk/create.py. During default install operations or environment transactions, an untrusted noarch:python package can instruct Conda to create or overwrite executables in the bin or Scripts directory or write files to directories outside the installation prefix if those parent directories already exist.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score is not available and the issue is not listed in CISA KEV, suggesting limited exploitation so far. The likely attack vector is local: an attacker who can influence the package feed or supply a malicious noarch:python package can subvert the entry‑point generation to write arbitrary files or replace execution wrappers. Successful exploitation would allow the installation user to run arbitrary Python code with their privileges and potentially compromise system configuration or other users sharing the same Conda installation.
OpenCVE Enrichment