Executive brief
conda-smithy is a tool used to manage and build software packages within the conda-forge ecosystem. A security flaw allowed unauthorized individuals to gain write access to software repositories by registering expired GitHub usernames previously belonging to legitimate maintainers. This could allow an attacker to inject malicious code into software packages, creating a significant supply chain risk for all users of the affected software.
Technical details
A logical privilege escalation vulnerability exists in conda-smithy due to the use of mutable GitHub usernames rather than immutable GitHub user IDs for repository invitation routing. When a maintainer changes their GitHub username, the old username becomes available for registration by third parties. An attacker who registers a recycled username can receive and accept pending or future repository invitations intended for the original maintainer. This grants the attacker write access to feedstock repositories, enabling them to modify build scripts or metadata. The issue is resolved in version 3.61.0 by transitioning to stable GitHub user IDs for identity verification.
Affected products
- conda-forge conda-smithy < 3.61.0
Timeline
- 2026-06-15: advisory: GitHub security advisory published by maintainers.
- 2026-06-18: disclosed: CVE-2026-46699 published to NVD.
- 2026-06-18: patched: Fix released in version 3.61.0.