rattlercache and py-rattler were vulnerable to package-cache path traversal when handling package metadata from conda channels.
During cache materialization, the rattercache code used the package record build string as part of a cache key that was joined into a filesystem path. A malicious or untrusted channel could publish repodata with path separators or traversal components in that field, causing package contents to be written outside the configured package cache directory.
The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form.
Users should upgrade to a patched version and avoid untrusted conda channels.
// cvss v3.1 vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low
Checked 2026-09-26 at 01:04 UTC. The most recent advisory here was published 2026-07-09. Updated continuously from NVD, GHSA, OSV and CNA feeds.