Conda-build contains commands and tools to build conda packages. Prior to version 25.3.0, the pyproject.toml lists conda-index as a Python dependency. This package is not published in PyPI. An attacker could claim this namespace and upload arbitrary (malicious) code to the package, and then exploit pip install commands by injecting the malicious dependency in the solve. This issue has been fixed in version 25.3.0. A workaround involves using --no-deps for pip install-ing the project from the repository.
History

Tue, 17 Jun 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 16 Jun 2025 20:45:00 +0000

Type Values Removed Values Added
Description Conda-build contains commands and tools to build conda packages. Prior to version 25.3.0, the pyproject.toml lists conda-index as a Python dependency. This package is not published in PyPI. An attacker could claim this namespace and upload arbitrary (malicious) code to the package, and then exploit pip install commands by injecting the malicious dependency in the solve. This issue has been fixed in version 25.3.0. A workaround involves using --no-deps for pip install-ing the project from the repository.
Title Conda-build vulnerable to supply chain attack vector due to pyproject.toml referring to dependencies not present in PyPI
Weaknesses CWE-1357
References
Metrics cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-06-16T20:38:53.100Z

Updated: 2025-06-17T19:03:49.217Z

Reserved: 2025-04-10T12:51:12.282Z

Link: CVE-2025-32800

cve-icon Vulnrichment

Updated: 2025-06-17T19:03:36.490Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-16T21:15:23.847

Modified: 2025-06-17T20:50:23.507

Link: CVE-2025-32800

cve-icon Redhat

No data.