Shell Code Execution Vulnerability in Constructor Tool by Conda
CVE-2025-49823
What is CVE-2025-49823?
The Constructor tool, utilized for creating installers for conda packages, is susceptible to a shell code execution vulnerability. This issue arises from the way prior versions (before 3.11.3) process the installation prefix through an eval statement, allowing unsanitized user input to execute as shell code. Though the execution occurs with user privileges rather than root, an attacker can exploit this vulnerability by crafting a malicious installation path that injects arbitrary commands. User intervention is required for exploitation, emphasizing the need for vigilance during installation processes. The vulnerability has been addressed in version 3.11.3.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
constructor < 3.11.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
