Shell Code Execution Vulnerability in Constructor Tool by Conda
CVE-2025-49823
NONE
What is CVE-2025-49823?
The Constructor tool, utilized for creating installers for conda packages, is susceptible to a shell code execution vulnerability. This issue arises from the way prior versions (before 3.11.3) process the installation prefix through an eval statement, allowing unsanitized user input to execute as shell code. Though the execution occurs with user privileges rather than root, an attacker can exploit this vulnerability by crafting a malicious installation path that injects arbitrary commands. User intervention is required for exploitation, emphasizing the need for vigilance during installation processes. The vulnerability has been addressed in version 3.11.3.
Affected Version(s)
constructor < 3.11.3