Repository Access Flaw in conda-smithy by conda-forge
CVE-2026-46699

7.6HIGH

Key Information:

Vendor
CVE Published:
18 June 2026

What is CVE-2026-46699?

Prior to version 3.61.0, conda-smithy, a tool for building conda recipes, was susceptible to a security issue that permitted unauthorized write access to feedstock repositories. This vulnerability stemmed from employing mutable GitHub usernames for repository invitation routing instead of utilizing immutable GitHub user IDs. The issue was resolved in version 3.61.0, enhancing the security of repository management.

Affected Version(s)

conda-smithy < 3.61.0

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.