Shell Code Execution Vulnerability in Constructor Tool by Conda
CVE-2025-49823

NONE

Key Information:

Vendor

Conda

Vendor
CVE Published:
17 June 2025

What is CVE-2025-49823?

The Constructor tool, utilized for creating installers for conda packages, is susceptible to a shell code execution vulnerability. This issue arises from the way prior versions (before 3.11.3) process the installation prefix through an eval statement, allowing unsanitized user input to execute as shell code. Though the execution occurs with user privileges rather than root, an attacker can exploit this vulnerability by crafting a malicious installation path that injects arbitrary commands. User intervention is required for exploitation, emphasizing the need for vigilance during installation processes. The vulnerability has been addressed in version 3.11.3.

Affected Version(s)

constructor < 3.11.3

References

CVSS V3.1

Score:
Severity:
NONE
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-49823 : Shell Code Execution Vulnerability in Constructor Tool by Conda