---
id: CVE-2026-54533
aliases:
  - GHSA-x9f6-9rvm-mmrg
title: vantage6 node has an Improper Access Control issue
summary: vantage6 node has an Improper Access Control issue
severity: medium
vendor: vantage6
product: vantage6
ecosystem: pip
affected:
  - vantage6 < 5.0.0
patched:
  - vantage6 5.0.0
published: '2026-06-05'
updated: '2026-07-09'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-x9f6-9rvm-mmrg'
references:
  - url: >-
      https://github.com/vantage6/vantage6/security/advisories/GHSA-x9f6-9rvm-mmrg
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-54533'
  - url: 'https://github.com/vantage6/vantage6/issues/1932'
  - url: 'https://docs.vantage6.ai/usage/running-the-node/security'
  - url: 'https://github.com/vantage6/vantage6'
  - url: 'https://github.com/vantage6/vantage6/blob/main/docs/release_notes.rst#500'
tags:
  - osv
  - pip
epss: 0.00285
epssPercentile: 0.21326
ingestedAt: '2026-07-10T13:49:11.217Z'
---

## Overview

### Impact
Malicious algorithms can potentially access other algorithms input and output files.

### Patches
Todo

### Workarounds
Verify and restrict the algorithm containers that are allowed to run on your node. See [here](https://docs.vantage6.ai/usage/running-the-node/security) on how to do this.

### References
https://docs.vantage6.ai/usage/running-the-node/security

### For more information
If you have any questions or comments about this advisory:
* Email us at [vantage6@iknl.nl](mailto:vantage6@iknl.nl)

## Affected packages

- `vantage6 < 5.0.0`

## Remediation

Upgrade to a patched release:

- `vantage6 5.0.0`
