Access Control Vulnerability in Conda-forge Infrastructure by Anaconda
CVE-2025-31484
9.3CRITICAL
What is CVE-2025-31484?
A vulnerability in the Conda-forge infrastructure allowed unauthorized access to upload packages to the Conda-forge channel. During a specified period, the wrong token was used for Azure's cf-staging access, enabling any feedstock maintainer to bypass the established upload process. While security logs on anaconda.org were verified, no malicious packages were detected. This incident emphasizes the importance of maintaining strict access controls and proper token management within the infrastructure to mitigate similar risks in the future.
Affected Version(s)
infrastructure >= 2025-02-10, <= 2025-04-01
