CVE-2026-73652High▾ Twilightvantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an ownership check, allowing one algorithm developer to alter another developer's algorith…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an ownership check, allowing one algorithm developer to alter another developer's algorithm while it is pending or under review. The attacker can change metadata including the algorithm image or image tag, causing reviewers and nodes to trust a different image from the one originally submitted for approval. No fixed version is available as of this review.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
vantage6 <= 5.0.2Connected by shared product, vendor, weakness, or advisory.
GHSA-47w6-gwp4-w6vcHighvantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
CVE-2024-21649High· 8.8vantage6 remote code execution vulnerability
CVE-2023-22738Medium· 6.5vantage6 vulnerable to Improper Preservation of Permissions
CVE-2024-22193Low· 3.5vantage6 may create unencrypted tasks in encrypted collaboration
CVE-2023-41881Low· 3.7vantage6 does not properly delete linked resources when deleting a collaboration
CVE-2023-23930High· 7.2Pickle serialization vulnerable to Deserialization of Untrusted Data