CARGO · JULY 2026 · EARLY WARNING

Rattler Package Cache Path Traversal Vulnerability

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-H672-P7H7-97V9Severity: HIGH

An early warning has been issued regarding a reported vulnerability in the rattler_cache and py-rattler packages, which could allow path traversal in the package cache when handling metadata from untrusted conda channels.

What happened

The reported vulnerability, tracked as GHSA-H672-P7H7-97V9, affects the rattler_cache and py-rattler packages. It appears to enable path traversal outside the configured package cache directory if metadata from a malicious or untrusted conda channel is processed. This could potentially allow an attacker to write package contents to arbitrary locations on the filesystem.

The vulnerability is under investigation, and the affected versions are not definitively known at this time. However, it is recommended to upgrade to the latest patched versions of rattler_cache (0.9.0 or later) and py-rattler (0.24.0 or later) as a precaution. Additionally, users should avoid using untrusted conda channels until the issue is resolved.

For more detailed information, consult the primary source at https://github.com/conda/rattler/security/advisories/GHSA-h672-p7h7-97v9. The situation is fluid, and further updates may be forthcoming as the investigation continues.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If rattler_cache is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats