CVE-2025-27510

conda-forge-metadata provides programatic access to conda-forge's metadata. conda-forge-metadata uses an optional dependency - "conda-oci-mirror" which was neither present on the PyPi repository nor registered by any entity. If conda-oci-mirror is taken over by a threat actor, it can result in remote code execution.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2025-03-04 22:15

Updated : 2025-03-05 17:15


NVD link : CVE-2025-27510

Mitre link : CVE-2025-27510

CVE.ORG link : CVE-2025-27510


JSON object : View

Products Affected

No product.

CWE
CWE-829

Inclusion of Functionality from Untrusted Control Sphere