Feed/CVE-2026-53956
CVE-2026-53956MEDIUMCVSS 5.4

Rattler vulnerable to package cache path traversal via conda package build string

Published Jul 9, 2026·Updated Jul 9, 2026

NVD Description

`rattler_cache` and `py-rattler` were vulnerable to package-cache path traversal when handling package metadata from conda channels. During cache materialization, the `ratter_cache` code used the package record `build` string as part of a cache key that was joined into a filesystem path. A malicious or untrusted channel could publish repodata with path separators or traversal components in that field, causing package contents to be written outside the configured package cache directory. The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels.

Affected Packages (2)

py_rattlerPYPI
Fixed in = 0.23.2
rattler_cacheCARGO
Fixed in = 0.8.2

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free