CVE Explorer
CVE-2026-46699
conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a single repository. Prior to version 3.61.0, a vulnerability in the conda-forge automated webservices allowed unintended write access to feedstock repositories through GitHub username takeover. The root cause is the use of mutable GitHub usernames as identifiers for repository invitation routing, rather than stable, immutable GitHub user IDs. Version 3.61.0 fixes the issue.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"conda-smithy","vendor":"conda-forge","versions":[{"status":"affected","version":"< 3.61.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f388712c26ce6066767b7ba0a25d4e5af20e5c33dfde4065d5cb978e07f8360f · sha256:811d90fa495aedd7… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":7.6,"baseSeverity":"HIGH","confidentialityImpact":"LOW","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f388712c26ce6066767b7ba0a25d4e5af20e5c33dfde4065d5cb978e07f8360f · sha256:811d90fa495aedd7… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-284","description":"CWE-284: Improper Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f388712c26ce6066767b7ba0a25d4e5af20e5c33dfde4065d5cb978e07f8360f · sha256:811d90fa495aedd7… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/conda-forge/conda-smithy/commit/3b0bcd92ebd6f41edd341401d84583a20911c587","tags":["x_refsource_MISC"],"url":"https://github.com/conda-forge/conda-smithy/commit/3b0bcd92ebd6f41edd341401d84583a20911c587"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f388712c26ce6066767b7ba0a25d4e5af20e5c33dfde4065d5cb978e07f8360f · sha256:811d90fa495aedd7… · /containers/cna/references/1
{"name":"https://github.com/conda-forge/conda-smithy/security/advisories/GHSA-g95q-3cmj-fvh8","tags":["x_refsource_CONFIRM"],"url":"https://github.com/conda-forge/conda-smithy/security/advisories/GHSA-g95q-3cmj-fvh8"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f388712c26ce6066767b7ba0a25d4e5af20e5c33dfde4065d5cb978e07f8360f · sha256:811d90fa495aedd7… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.