VYPR

rattler_cache

by Rattler

CVEs (1)

  • CVE-2026-53956medJul 9, 2026
    risk 0.26cvss epss

    `rattler_cache` and `py-rattler` were vulnerable to package-cache path traversal when handling package metadata from conda channels. During cache materialization, the `ratter_cache` code used the package record `build` string as part of a cache key that was joined into a…