CVE-2026-53956
Deferred Deferred - Pending Action

Path Traversal in Rattler Cache Library

Vulnerability report for CVE-2026-53956, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-10

Assigner: GitHub, Inc.

Description

Rattler is a library that provides common functionality used within the conda ecosystem. `rattler_cache` prior to version 0.9.0 and `py-rattler` prior to version 0.24.0 were vulnerable to package-cache path traversal when handling package metadata from conda channels. During cache materialization, the `ratter_cache` code used the package record `build` string as part of a cache key that was joined into a filesystem path. A malicious or untrusted channel could publish repodata with path separators or traversal components in that field, causing package contents to be written outside the configured package cache directory. The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to `rattler_cache` version 0.9.0 or `py-rattler` version 0.24.0 and avoid untrusted conda channels.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-10
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Rattler is a library used in the conda ecosystem for managing packages. Versions prior to 0.9.0 (rattler_cache) and 0.24.0 (py-rattler) had a vulnerability where package-cache path traversal could occur when processing package metadata from conda channels. The build string in package records was used as part of a cache key, which could include path separators or traversal components. This allowed malicious channels to write package contents outside the intended cache directory.

Detection Guidance

To detect this vulnerability, check the installed versions of rattler_cache or py-rattler. Run 'conda list rattler_cache' or 'pip show py-rattler' to verify versions. Ensure you are not using untrusted conda channels.

Impact Analysis

This vulnerability could allow an attacker to write files outside the configured package cache directory by exploiting a malicious or untrusted conda channel. This might lead to unauthorized file modifications, potential system compromise, or disruption of package management operations. Users are advised to upgrade to patched versions and avoid untrusted channels.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR or HIPAA if it leads to unauthorized access or modification of sensitive data. The path traversal flaw might allow attackers to write files outside the intended cache directory, potentially exposing or altering protected health information or personal data. However, the risk depends on whether untrusted conda channels are used, as curated channels are expected to mitigate this issue.

Mitigation Strategies

Upgrade rattler_cache to version 0.9.0 or higher and py-rattler to version 0.24.0 or higher. Avoid using untrusted conda channels. Review and remove any malicious or untrusted channels from your conda configuration.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-53956. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart