Path Traversal Vulnerability in Conda-build by Anaconda, Inc.
CVE-2025-32799
What is CVE-2025-32799?
Conda-build, a tool for building conda packages developed by Anaconda, Inc., is subject to a path traversal vulnerability due to improper sanitization of tar entry paths. This vulnerability allows attackers to craft malicious tar archives containing directory traversal sequences. Consequently, this undermines the intended extraction directory, enabling unauthorized file writes, which could lead to arbitrary file overwrites, privilege escalation, or potential code execution targeting sensitive system locations. The issue has been rectified in version 25.4.0.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
conda-build < 25.4.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
