Critical severity9.8NVD Advisory· Published Jun 16, 2025· Updated Jun 17, 2026
CVE-2025-32800
CVE-2025-32800
Description
Conda-build contains commands and tools to build conda packages. Prior to version 25.3.0, the pyproject.toml lists conda-index as a Python dependency. This package is not published in PyPI. An attacker could claim this namespace and upload arbitrary (malicious) code to the package, and then exploit pip install commands by injecting the malicious dependency in the solve. This issue has been fixed in version 25.3.0. A workaround involves using --no-deps for pip install-ing the project from the repository.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<25.3.0+ 1 more
- (no CPE)range: <25.3.0
- (no CPE)range: < 25.3.0
Patches
Vulnerability mechanics
References
3- github.com/conda/conda-build/commit/f5a6aeef0d5d6940b8c2a88796910dc7476a62bbnvdPatch
- drive.google.com/file/d/18qe97zxcpTn2l84187A9meGCi2Wg-n_Y/viewnvdExploitTechnical Description
- github.com/conda/conda-build/security/advisories/GHSA-83gh-p93g-cwgxnvdVendor Advisory
News mentions
0No linked articles in our index yet.