CVE-2025-32784 - CVE House
Back to Database
Status published High CVE-2025-32784

conda-forge-webservices has an Unauthorized Artifact Modification Race Condition

Vulnerability Description

conda-forge-webservices is the web app deployed to run conda-forge admin commands and linting. In versions prior to 2025.4.10, a race condition vulnerability has been identified in the conda-forge-webservices component used within the shared build infrastructure. This vulnerability, categorized as a Time-of-Check to Time-of-Use (TOCTOU) issue, can be exploited to introduce unauthorized modifications to build artifacts stored in the cf-staging Anaconda channel. Exploitation may result in the unauthorized publication of malicious artifacts to the production conda-forge channel. The core vulnerability results from the absence of atomicity between the hash validation and the artifact copy operation. This gap allows an attacker, with access to the cf-staging token, to overwrite the validated artifact with a malicious version immediately after hash verification, but before the copy action is executed. As the cf-staging channel permits artifact overwrites, such an operation can be carried out using the anaconda upload --force command. This vulnerability is fixed in 2025.4.10.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-32784

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

conda-forge

View all reports →

Affected Software

conda-forge-webservices
Vulnerable Versions:
< 2025.4.10

Timeline

Official Publish: April 15th, 2025
Last Modified: April 17th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)