(conda) Constructor is a tool which allows constructing an installer for a collection of conda packages. Prior to version 3.11.3, shell installer scripts process the installation prefix (user_prefix) using an eval statement, which executes unsanitized user input as shell code. Although the script runs with user privileges (not root), an attacker could exploit this by injecting arbitrary commands through a malicious path during installation. Exploitation requires explicit user action. This issue has been patched in version 3.11.3.
Metrics
Affected Vendors & Products
References
History
Tue, 17 Jun 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 17 Jun 2025 02:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | (conda) Constructor is a tool which allows constructing an installer for a collection of conda packages. Prior to version 3.11.3, shell installer scripts process the installation prefix (user_prefix) using an eval statement, which executes unsanitized user input as shell code. Although the script runs with user privileges (not root), an attacker could exploit this by injecting arbitrary commands through a malicious path during installation. Exploitation requires explicit user action. This issue has been patched in version 3.11.3. | |
Title | Conda Constructor Command Injection via Unsanitized User Input (Low) | |
Weaknesses | CWE-77 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-06-17T02:21:17.496Z
Updated: 2025-06-17T15:52:25.295Z
Reserved: 2025-06-11T14:33:57.798Z
Link: CVE-2025-49823

Updated: 2025-06-17T15:52:16.702Z

Status : Awaiting Analysis
Published: 2025-06-17T03:15:24.580
Modified: 2025-06-17T20:50:23.507
Link: CVE-2025-49823

No data.