Directory Traversal Vulnerability in Rattler Library by Conda
CVE-2026-47425

6.9MEDIUM

Key Information:

Vendor

Conda

Vendor
CVE Published:
21 July 2026

What is CVE-2026-47425?

The Rattler library, utilized in the Conda ecosystem for package management, contains a vulnerability where the EntryPoint::FromStr method inadequately sanitizes the command field. This flaw allows a malicious noarch:python package to craft an entry-point name that employs directory traversal sequences, enabling unauthorized write access outside the intended directory structure. As a result, critical files may be overwritten or created outside the designated install prefix, posing a significant security threat during the installation of packages. Version 0.43.2 and above mitigate this vulnerability effectively.

Affected Version(s)

pixi < 0.69.0

py-rattler < 0.24.0

rattler < 0.43.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.