Path Traversal Vulnerability in Rattler Library by Conda
CVE-2026-53956

5.4MEDIUM

Key Information:

Vendor

Conda

Vendor
CVE Published:
9 September 2026

What is CVE-2026-53956?

The Rattler library, utilized within the conda ecosystem, contains a path traversal vulnerability affecting versions prior to 0.9.0 of rattler_cache and 0.24.0 of py-rattler. This vulnerability allows an attacker to exploit malicious or untrusted conda channels to manipulate package metadata, leading to potential writes outside the designated package cache directory. It is essential for users to avoid untrusted channels and to upgrade to the latest versions of the library to mitigate this issue.

Affected Version(s)

py-rattler < 0.24.0

rattler_cache < 0.9.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.