VYPR

pixi

by Prefix Dev

CVEs (1)

  • CVE-2026-47425Jun 1, 2026
    risk 0.00cvss epss

    ## Summary `EntryPoint::FromStr` in `rattler_conda_types` performs only `.trim()` on the `command` field before the linker joins it onto the install prefix and writes an executable Python script. A malicious `noarch:python` package can ship an `info/link.json` with an…