Description
vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an ownership check, allowing one algorithm developer to alter another developer's algorithm while it is pending or under review. The attacker can change metadata including the algorithm image or image tag, causing reviewers and nodes to trust a different image from the one originally submitted for approval. No fixed version is available as of this review.
Published: 2026-08-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the algorithm‑store edit permission of Vantage6 5.0.2 and earlier because it lacks an ownership check. This allows one developer to change another developer’s algorithm while it is pending or under review. By modifying metadata such as the algorithm image or image tag, the attacker can cause reviewers and nodes to use a different Docker image than the one originally submitted, undermining the integrity of the analysis workflow. Based on the description, it can be inferred that the use of a malicious image could lead to execution of code on analysis nodes.

Affected Systems

Any installation of Vantage6 5.0.2 or earlier is affected. The product is Vantage6, with no further sub‑components specified. A fixed version has not yet been released, so all instances prior to a future update remain vulnerable.

Risk and Exploitability

The CVSS score of 7.1 classifies the issue as high severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV, so the current exploitation frequency is unknown. Attacks require a developer‑level user with access to the algorithm store, so the likely attack vector is an internal actor exploiting the system’s permission model. The absence of an ownership check directly allows unauthorized modification of algorithm metadata.

Generated by OpenCVE AI on August 13, 2026 at 20:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Configure the system to enforce ownership checks on algorithm edits, ensuring only the original developer can modify algorithms that are pending or under review.
  • Revoke edit permissions for pending or under‑review algorithms until an official patch is released; restrict this capability to authorized roles using role‑based access control.
  • Implement image verification by requiring signed Docker images or calculating checksums for algorithm images before nodes accept them, reducing the likelihood of a malicious image being used.
  • Continuously monitor audit logs for unexpected modifications to algorithm metadata and notify administrators.

Generated by OpenCVE AI on August 13, 2026 at 20:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-47w6-gwp4-w6vc vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
History

Thu, 13 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Vantage6
Vantage6 vantage6
Vendors & Products Vantage6
Vantage6 vantage6

Thu, 13 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an ownership check, allowing one algorithm developer to alter another developer's algorithm while it is pending or under review. The attacker can change metadata including the algorithm image or image tag, causing reviewers and nodes to trust a different image from the one originally submitted for approval. No fixed version is available as of this review.
Title vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Vantage6 Vantage6
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-13T18:57:28.520Z

Reserved: 2026-08-13T14:04:09.604Z

Link: CVE-2026-73652

cve-icon Vulnrichment

Updated: 2026-08-13T18:57:25.951Z

cve-icon NVD

Status : Received

Published: 2026-08-13T19:17:38.770

Modified: 2026-08-13T20:17:29.897

Link: CVE-2026-73652

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T21:00:06Z

Weaknesses