Junglewise Threat Intelligence

CVE-2026-53956: Rattler is a library that provides common functionality used within the conda ecosystem. `rattler_cache` prior to version 0.9.0 and `py-ratt

CVE-2026-53956 · Severity: medium · CVSS 5.4 · Published 2026-09-09

Vendors: crates.io, PyPI.

Executive brief

Rattler, a tool used for managing Conda software packages, is vulnerable to a flaw that allows malicious package sources to write files to unauthorized locations on a user's computer. If a user connects to an untrusted or compromised package channel, an attacker could potentially overwrite system files or plant malicious software outside of the intended storage area. This could lead to system instability or unauthorized access to the user's environment.

Technical details

A path traversal vulnerability (CWE-22, CWE-73) exists in rattler_cache and py-rattler during the cache materialization process. The software fails to sanitize the 'build' string from package metadata before using it as a key to construct filesystem paths. An attacker controlling a conda channel can provide a malicious 'build' string containing path traversal sequences (e.g., '../'), causing the library to write package contents to arbitrary locations on the host filesystem. Exploitation requires the victim to use an untrusted conda channel. The issue is fixed in rattler_cache 0.9.0 and py-rattler 0.24.0.

Affected products

  • conda rattler_cache <= 0.8.2
  • conda py-rattler <= 0.23.2

Timeline

  • 2026-06-02: disclosed: Initial disclosure by maintainers
  • 2026-07-09: advisory: GitHub Advisory published

References

Related threats