---
id: CVE-2023-22738
aliases:
  - GHSA-vvjv-97j8-94xh
  - PYSEC-2023-53
title: vantage6 vulnerable to Improper Preservation of Permissions
summary: vantage6 vulnerable to Improper Preservation of Permissions
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
vendor: vantage6
product: vantage6
ecosystem: pip
affected:
  - vantage6 < 3.8.0
patched:
  - vantage6 3.8.0
published: '2023-02-28'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:49:52.116471668Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-vvjv-97j8-94xh'
references:
  - url: >-
      https://github.com/vantage6/vantage6/security/advisories/GHSA-vvjv-97j8-94xh
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-22738'
  - url: >-
      https://github.com/vantage6/vantage6/commit/798aca1de142a4eca175ef51112e2235642f4f24
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/vantage6/PYSEC-2023-53.yaml
  - url: 'https://github.com/vantage6/vantage6'
tags:
  - osv
  - pip
epss: 0.00375
epssPercentile: 0.28767
ingestedAt: '2026-09-12T03:13:01.732Z'
---

## Overview

### Impact
Assigning existing users to a different organization is currently possible. It may lead to unintended access: if a user from organization A is accidentally assigned to organization B, they will retain their permissions and therefore might be able to access stuff they should not be allowed to access.

### Patches
Update to 3.8.0

### Workarounds
None

### References
None

### For more information
If you have any questions or comments about this advisory:
* Email us at [vantage6@iknl.nl](mailto:vantage6@iknl.nl)


## Affected packages

- `vantage6 < 3.8.0`

## Remediation

Upgrade to a patched release:

- `vantage6 3.8.0`
