Race Condition Vulnerability in Conda-Forge Web Services
CVE-2025-32784

7.5HIGH

Key Information:

Vendor
CVE Published:
15 April 2025

What is CVE-2025-32784?

A race condition vulnerability has been discovered in the conda-forge-webservices, particularly before version 2025.4.10. This Time-of-Check to Time-of-Use (TOCTOU) issue allows an attacker with access to the cf-staging token to exploit a window of vulnerability between hash validation and the copy operation of build artifacts. By exploiting this flaw, unauthorized modifications can be made to build artifacts, potentially enabling the publication of malicious artifacts to the production conda-forge channel. The lack of atomicity in the hash validation and copy process is the root cause of this security flaw. The vulnerability has been resolved in version 2025.4.10, making it essential for users to upgrade to mitigate risks.

Affected Version(s)

conda-forge-webservices < 2025.4.10

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.