All 3 CVE vulnerabilities found in conda-smithy, with AI-generated Chinese analysis, references, and POCs.
Vendor: conda-forge
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-46699 | conda-smithy vulnerable to misrouted repository invitation by conda-forge-webservices[bot] due to GitHub username takeover leading to unintended write access in conda-forge feedstock repository CWE-284 | 7.6 | High | 2026-06-18 |
| CVE-2025-49824 | conda-smithy Insecure Encryption Vulnerable to Oracle Padding Attack CWE-200 | 5.9AI | Medium AI | 2025-06-17 |
| CVE-2025-49843 | conda-smithy Has Incorrect Default File Permissions CWE-276 | 8.1AI | High AI | 2025-06-17 |
All 3 known CVE vulnerabilities affecting conda-smithy with full Chinese analysis, references, and POCs where available.