CVE-2025-27510
Description
conda-forge-metadata provides programatic access to conda-forge's metadata. conda-forge-metadata uses an optional dependency - "conda-oci-mirror" which was neither present on the PyPi repository nor registered by any entity. If conda-oci-mirror is taken over by a threat actor, it can result in remote code execution.
Is your site exposed to CVE-2025-27510?
Run a free security scan — no signup, results in seconds.
Weakness Type (CWE)
References
Other References
Frequently Asked Questions
What is CVE-2025-27510? +
How do I check if I'm vulnerable to CVE-2025-27510? +
Related Vulnerabilities
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. …
Collabora Online is a collaborative online office suite based on LibreOffice. Macro support is disabled by default in Collabora Online, …
A critical security vulnerability exists in remote cache extensions for common build systems utilizing bucket-based remote cache (such as those …
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules …
In Duck Site before version 1.0.1, the repository has a deploy workflow that runs after the build workflow completes. The …
An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the SSH server on B&R APROL <4.4-00P1 may allow an …