No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-47w6-gwp4-w6vc | vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review |
Thu, 13 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vantage6
Vantage6 vantage6 |
|
| Vendors & Products |
Vantage6
Vantage6 vantage6 |
Thu, 13 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an ownership check, allowing one algorithm developer to alter another developer's algorithm while it is pending or under review. The attacker can change metadata including the algorithm image or image tag, causing reviewers and nodes to trust a different image from the one originally submitted for approval. No fixed version is available as of this review. | |
| Title | vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-13T18:57:28.520Z
Reserved: 2026-08-13T14:04:09.604Z
Link: CVE-2026-73652
Updated: 2026-08-13T18:57:25.951Z
Status : Received
Published: 2026-08-13T19:17:38.770
Modified: 2026-08-13T20:17:29.897
Link: CVE-2026-73652
No data.
OpenCVE Enrichment
Updated: 2026-08-13T19:45:17Z
-
CWE-863
Incorrect Authorization
Github GHSA