CVE-2025-32797 is a race condition vulnerability in conda-build versions prior to 25.3.1, affecting anaconda conda_build. The write_build_scripts function creates temporary build scripts with overly permissive 0o766 permissions, allowing attackers with filesystem access to overwrite the script before execution. This enables arbitrary code execution under the victim's privileges, posing a significant risk in shared environments and potentially leading to full system compromise. With a CVSS score of 7.0 (HIGH), the attack vector is local with high attack complexity, but requires low privileges and no user interaction, leading to high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 25.3.1CPE matchmatch criteria | cpe:2.3:a:anaconda:conda-build:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.