Local File Permission Vulnerability in Constructor by conda
CVE-2025-64343
What is CVE-2025-64343?
The Constructor tool from conda enables users to create custom installers for conda package collections. In versions up to and including 3.12.2, the installation directory inherits permissions from its parent directory, which can lead to overly permissive settings, allowing authenticated users to write within the directory. This creates a potential vulnerability for local users if the installation occurs in a shared directory. It is crucial to be aware of this exposure as modifications can be made by any logged-in user during both single-user and all-user installations, with permissions persisting after installation. Version 3.13.0 addresses this issue by enhancing the permission settings.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
constructor < 3.13.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
