{"id":"CVE-2026-54533","aliases":["GHSA-x9f6-9rvm-mmrg"],"title":"vantage6 node has an Improper Access Control issue","summary":"vantage6 node has an Improper Access Control issue","severity":"medium","vendor":"vantage6","product":"vantage6","ecosystem":"pip","affected":["vantage6 < 5.0.0"],"patched":["vantage6 5.0.0"],"published":"2026-06-05","updated":"2026-07-09","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-x9f6-9rvm-mmrg","references":[{"url":"https://github.com/vantage6/vantage6/security/advisories/GHSA-x9f6-9rvm-mmrg"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54533"},{"url":"https://github.com/vantage6/vantage6/issues/1932"},{"url":"https://docs.vantage6.ai/usage/running-the-node/security"},{"url":"https://github.com/vantage6/vantage6"},{"url":"https://github.com/vantage6/vantage6/blob/main/docs/release_notes.rst#500"}],"tags":["osv","pip"],"epss":0.00285,"epssPercentile":0.21326,"ingestedAt":"2026-07-10T13:49:11.217Z","slug":"CVE-2026-54533","body":"## Overview\n\n### Impact\nMalicious algorithms can potentially access other algorithms input and output files.\n\n### Patches\nTodo\n\n### Workarounds\nVerify and restrict the algorithm containers that are allowed to run on your node. See [here](https://docs.vantage6.ai/usage/running-the-node/security) on how to do this.\n\n### References\nhttps://docs.vantage6.ai/usage/running-the-node/security\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Email us at [vantage6@iknl.nl](mailto:vantage6@iknl.nl)\n\n## Affected packages\n\n- `vantage6 < 5.0.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `vantage6 5.0.0`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}