Race Condition Vulnerability in Conda-Forge Web Services
CVE-2025-32784
What is CVE-2025-32784?
A race condition vulnerability has been discovered in the conda-forge-webservices, particularly before version 2025.4.10. This Time-of-Check to Time-of-Use (TOCTOU) issue allows an attacker with access to the cf-staging token to exploit a window of vulnerability between hash validation and the copy operation of build artifacts. By exploiting this flaw, unauthorized modifications can be made to build artifacts, potentially enabling the publication of malicious artifacts to the production conda-forge channel. The lack of atomicity in the hash validation and copy process is the root cause of this security flaw. The vulnerability has been resolved in version 2025.4.10, making it essential for users to upgrade to mitigate risks.
Affected Version(s)
conda-forge-webservices < 2025.4.10
