Race Condition Vulnerability in Conda-Forge Web Services
CVE-2025-32784
What is CVE-2025-32784?
A race condition vulnerability has been discovered in the conda-forge-webservices, particularly before version 2025.4.10. This Time-of-Check to Time-of-Use (TOCTOU) issue allows an attacker with access to the cf-staging token to exploit a window of vulnerability between hash validation and the copy operation of build artifacts. By exploiting this flaw, unauthorized modifications can be made to build artifacts, potentially enabling the publication of malicious artifacts to the production conda-forge channel. The lack of atomicity in the hash validation and copy process is the root cause of this security flaw. The vulnerability has been resolved in version 2025.4.10, making it essential for users to upgrade to mitigate risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
conda-forge-webservices < 2025.4.10
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
