Impact
The vulnerability exists in the algorithm‑store edit permission of Vantage6 5.0.2 and earlier because it lacks an ownership check. This allows one developer to change another developer’s algorithm while it is pending or under review. By modifying metadata such as the algorithm image or image tag, the attacker can cause reviewers and nodes to use a different Docker image than the one originally submitted, undermining the integrity of the analysis workflow. Based on the description, it can be inferred that the use of a malicious image could lead to execution of code on analysis nodes.
Affected Systems
Any installation of Vantage6 5.0.2 or earlier is affected. The product is Vantage6, with no further sub‑components specified. A fixed version has not yet been released, so all instances prior to a future update remain vulnerable.
Risk and Exploitability
The CVSS score of 7.1 classifies the issue as high severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV, so the current exploitation frequency is unknown. Attacks require a developer‑level user with access to the algorithm store, so the likely attack vector is an internal actor exploiting the system’s permission model. The absence of an ownership check directly allows unauthorized modification of algorithm metadata.
OpenCVE Enrichment
Github GHSA