Conda's vulnerability profile centers on its Miniconda3 package-management product, a widely used environment and dependency resolver for scientific and data-science workflows. The durable signal is rooted in permission-assignment and command-injection weaknesses, reflecting the risks inherent to a package manager that orchestrates installations and executes build and activation scripts with elevated privilege. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Conda over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-46062HIGH Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writabl | Dec 17, 2025 | 7.8 | 25 | NO | NO |
CVE-2022-26526HIGH Anaconda Anaconda3 (Anaconda Distribution) through 2021.11.0.0 and Miniconda3 through 4.11.0.0 can create a world-writable directory under %PROGRAMDATA% and place that directory in | Mar 17, 2022 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Conda.
Media articles that mention a CVE ID that affects a product developed by Conda — matched by CVE ID, not by vendor name.