First published: Tue Mar 04 2025(Updated: )
conda-forge-metadata provides programatic access to conda-forge's metadata. conda-forge-metadata uses an optional dependency - "conda-oci-mirror" which was neither present on the PyPi repository nor registered by any entity. If conda-oci-mirror is taken over by a threat actor, it can result in remote code execution.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
conda-forge-metadata |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27510 is categorized as a severity risk due to the potential takeover of the 'conda-oci-mirror' dependency.
To mitigate CVE-2025-27510, ensure that 'conda-oci-mirror' is not being used or monitored closely for unauthorized changes.
Users of conda-forge-metadata could be at risk of malicious activity if the optional 'conda-oci-mirror' dependency is compromised.
No, 'conda-oci-mirror' is not present on the PyPi repository or officially registered, which heightens its risk.
Developers and organizations using conda-forge-metadata should be particularly vigilant regarding CVE-2025-27510.