CVE-2026-53956
Last modified
CVE-2026-53956 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Rattler is a library that provides common functionality used within the conda ecosystem. `rattler_cache` prior to version 0.9.0 and `py-rattler` prior to version 0.24.0 were vulnerable to package-cache path traversal when handling package metadata from conda channels. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
Rattler is a library that provides common functionality used within the conda ecosystem. `rattler_cache` prior to version 0.9.0 and `py-rattler` prior to version 0.24.0 were vulnerable to package-cache path traversal when handling package metadata from conda channels. During cache materialization, the `ratter_cache` code used the package record `build` string as part of a cache key that was joined into a filesystem path. A malicious or untrusted channel could publish repodata with path separators or traversal components in that field, causing package contents to be written outside the configured package cache directory. The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to `rattler_cache` version 0.9.0 or `py-rattler` version 0.24.0 and avoid untrusted conda channels.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| conda | rattler_cache | < 0.9.0 |
| conda | py-rattler | < 0.24.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-53956?
How severe is CVE-2026-53956?
How do I fix CVE-2026-53956?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-53949Ghost is a Node.js content management system. From 5.46.1 un…5.3
- CVE-2026-5395The Fluent Forms – Customizable Contact Forms, Survey, Quiz,…8.2
- CVE-2026-53950@tryghost/activitypub is Ghost’s social/federation client ap…7.5
- CVE-2026-53951Copier is a library and CLI app for rendering project templa…8.8
- CVE-2026-53952GetSimple CMS is a content management system (CMS), and GetS…9.8
- CVE-2026-53954Bugsink is a self-hosted error tracking tool. Prior to versi…4.3
- CVE-2026-53957Contentful MCP Server is a Model Context Protocol server for…7.7
- CVE-2026-539584gaBoards is a boards system for realtime project management…7.6
- CVE-2026-539594gaBoards is a boards system for realtime project management…6.5
- CVE-2026-5396The Fluent Forms plugin for WordPress is vulnerable to Autho…8.2
- CVE-2026-53960Discourse is an open-source discussion platform. Prior to 20…5.3
- CVE-2026-53961Discourse is an open-source discussion platform. Prior to 20…6.5
Are you affected by CVE-2026-53956?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
