Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-53956— Rattler vulnerable to package cache path traversal via conda package build string

Quick assessment

Affected
conda rattler_cache
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Rattler 是一个为 Conda 生态系统提供通用功能的库。 在 0.9.0 版本之前,以及 在 0.24.0 版本之前,在处理来自 Conda 渠道的包元数据时,存在包缓存路径遍历(path traversal)漏洞。 在缓存物化(cache materialization)过程中, 代码将包记录的 字符串用作缓存键的一部分,并将其拼接到文件系统路径中。恶意或不可信的渠道可以发布包含路径分隔符或遍历组件(如 )的 ,导致包的内容被写入到配置的包缓存目录之外。 该问题要求使用恶意或不可信的 Conda 渠道才会

CVSS 5.4 · Medium EPSS 0.03% · P10
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-53956

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Rattler vulnerable to package cache path traversal via conda package build string
Source: CVE Program / CVE List V5
Vulnerability Description
Rattler is a library that provides common functionality used within the conda ecosystem. `rattler_cache` prior to version 0.9.0 and `py-rattler` prior to version 0.24.0 were vulnerable to package-cache path traversal when handling package metadata from conda channels. During cache materialization, the `ratter_cache` code used the package record `build` string as part of a cache key that was joined into a filesystem path. A malicious or untrusted channel could publish repodata with path separators or traversal components in that field, causing package contents to be written outside the configured package cache directory. The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to `rattler_cache` version 0.9.0 or `py-rattler` version 0.24.0 and avoid untrusted conda channels.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
conda rattler_cache < 0.9.0 -
conda py-rattler < 0.24.0 -

II. Public POCs for CVE-2026-53956

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-53956

登录查看更多情报信息。

Vendor Advisories for CVE-2026-53956 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-53956

No comments yet


Leave a comment