CVE Database
/

CVE-2025-49842

Back to search

CVE-2025-49842

Published: Jun 17, 2025

Modified: Jun 17, 2025

PUBLISHED

Description

conda-forge-webservices is the web app deployed to run conda-forge admin commands and linting. Prior to version 2025.3.24, the conda_forge_webservice Docker container executes commands without specifying a user. By default, Docker containers run as the root user, which increases the risk of privilege escalation and host compromise if a vulnerability is exploited. This issue has been patched in version 2025.3.24.

VendorProductVersions

conda-forge

conda-forge-webservices

affected
< 2025.3.24

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now