VYPR
Vendor

Anaconda

Products
4
CVEs
11
Across products
13
Status
Private

Products

4

Recent CVEs

11
  • CVE-2021-42969HigMay 13, 2022
    risk 0.57cvss 8.8epss 0.02

    Certain Anaconda3 2021.05 are affected by OS command injection. When a user installs Anaconda, an attacker can create a new file and write something in usercustomize.py. When the user opens the terminal or activates Anaconda, the command will be executed.

  • CVE-2021-42343CriOct 26, 2021
    risk 0.57cvss 9.8epss 0.03

    An issue was discovered in the Dask distributed package before 2021.10.0 for Python. Single machine Dask clusters started with dask.distributed.LocalCluster or dask.distributed.Client (which defaults to using LocalCluster) would mistakenly configure their respective Dask workers…

  • CVE-2024-46062HigDec 17, 2025
    risk 0.51cvss 7.8epss 0.00

    Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This flaw allows a local low-privileged user…

  • CVE-2024-46060HigDec 17, 2025
    risk 0.51cvss 7.8epss 0.00

    Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This allows a local low-privileged user to…

  • CVE-2022-26526HigMar 17, 2022
    risk 0.51cvss 7.8epss 0.00

    Anaconda Anaconda3 (Anaconda Distribution) through 2021.11.0.0 and Miniconda3 through 4.11.0.0 can create a world-writable directory under %PROGRAMDATA% and place that directory into the system PATH environment variable. Thus, for example, local users can gain privileges by…

  • CVE-2026-23528MedJan 16, 2026
    risk 0.33cvss 6.1epss 0.00

    Dask distributed is a distributed task scheduler for Dask. Prior to 2026.1.0, when Jupyter Lab, jupyter-server-proxy, and Dask distributed are all run together, it is possible to craft a URL which will result in code being executed by Jupyter due to a cross-side-scripting (XSS)…

  • CVE-2023-35845MedSep 11, 2023
    risk 0.31cvss 4.7epss 0.00

    Anaconda 3 2023.03-1-Linux allows local users to disrupt TLS certificate validation by modifying the cacert.pem file used by the installed pip program. This occurs because many files are installed as world-writable on Linux, ignoring umask, even when these files are installed as…

  • CVE-2025-32800CriJun 16, 2025
    risk 0.00cvss 9.8epss 0.01

    Conda-build contains commands and tools to build conda packages. Prior to version 25.3.0, the pyproject.toml lists conda-index as a Python dependency. This package is not published in PyPI. An attacker could claim this namespace and upload arbitrary (malicious) code to the…

  • CVE-2025-32799CriJun 16, 2025
    risk 0.00cvss 9.8epss 0.01

    Conda-build contains commands and tools to build conda packages. Prior to version 25.4.0, the conda-build processing logic is vulnerable to path traversal (Tarslip) attacks due to improper sanitization of tar entry paths. Attackers can craft tar archives containing entries with…

  • CVE-2025-32798CriJun 16, 2025
    risk 0.00cvss 9.8epss 0.01

    Conda-build contains commands and tools to build conda packages. Prior to version 25.4.0, the conda-build recipe processing logic has been found to be vulnerable to arbitrary code execution due to unsafe evaluation of recipe selectors. Currently, conda-build uses the eval…

  • CVE-2025-32797HigJun 16, 2025
    risk 0.00cvss 7.0epss 0.00

    Conda-build contains commands and tools to build conda packages. Prior to version 25.3.1, the write_build_scripts function in conda-build creates the temporary build script conda_build.sh with overly permissive file permissions (0o766), allowing write access to all users.…