py-rattler
Rust crates to work with the Conda ecosystem.
Activity
- Latest release
- 3d ago
- Total releases
- 39
- Cadence
- ~13 days
- Last 12 months
- 13
Reach
- Stars
- 455
Details
- License
- BSD-3-Clause
- First release
- Oct 06, 2023
| Version | Released | |
|---|---|---|
0.26.0
minor
| ||
0.25.0
minor
| ||
0.24.0
minor
| ||
0.23.2
patch
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.23.1
patch
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.23.0
minor
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.22.0
minor
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.21.0
minor
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.20.0
minor
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.19.0
minor
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.18.0
minor
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.17.0
minor
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.16.0
minor
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.15.0
minor
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.14.0
minor
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.13.1
patch
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.13.0
minor
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.12.0
minor
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.11.0
minor
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.10.0
minor
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.9.1
patch
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.9.0
minor
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.8.2
patch
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.8.0
minor
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.7.2
patch
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.7.1
patch
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.7.0
minor
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.6.3
patch
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.6.2
patch
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.6.1
patch
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.6.0
minor
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.0
minor
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.4.0
minor
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.3.0
minor
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.2.1
patch
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.2.0
minor
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.1.2
patch
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.1.1
patch
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.1.0
initial
2 CVEs
CVE-2026-53956
PYSEC-2026-2970
GHSA-h672-p7h7-97v9
Jul 13, 2026
Rattler vulnerable to package cache path traversal via conda package build string
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
Low
During cache materialization, the The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to a patched version and avoid untrusted conda channels. Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47425
PYSEC-2026-2971
GHSA-q53q-5r4j-5729
Jul 13, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Critical
Network
Low
None
Summary
Resolved in https://github.com/conda/rattler/pull/2445, released in rattler 0.43.2. Affected
ResearcherBerkant Koc me@berkoc.com PGP: 0C588DFD76204987284213EA0AC529C41F8AA5D6 Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.15.0
0.16.0
0.17.0
+ 24 more Show less
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.8.0
0.8.2
0.9.0
0.9.1
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev |