---
id: CVE-2026-73652
title: vantage6 is an open-source infrastructure for privacy preserving analysis
summary: >-
  vantage6 is an open-source infrastructure for privacy preserving analysis. In
  version 5.0.2 and earlier, the algorithm-store edit permission lacks an
  ownership check, allowing one algorithm developer to alter another developer's
  algorith…
severity: high
cwe:
  - CWE-863
vendor: vantage6
product: vantage6
affected:
  - vantage6 <= 5.0.2
published: '2026-08-13'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T20:09:01.757'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73652'
references:
  - url: >-
      https://github.com/vantage6/vantage6/security/advisories/GHSA-47w6-gwp4-w6vc
    label: security-advisories@github.com
  - url: 'https://github.com/vantage6/vantage6'
tags:
  - nvd
  - osv
  - pip
epss: 0.00207
epssPercentile: 0.11133
aliases:
  - GHSA-47w6-gwp4-w6vc
ecosystem: pip
ingestedAt: '2026-08-13T19:18:20.460Z'
---

## Overview

vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an ownership check, allowing one algorithm developer to alter another developer's algorithm while it is pending or under review. The attacker can change metadata including the algorithm image or image tag, causing reviewers and nodes to trust a different image from the one originally submitted for approval. No fixed version is available as of this review.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-73652)

Affected packages:

- `vantage6 <= 5.0.2`

Source: https://osv.dev/vulnerability/GHSA-47w6-gwp4-w6vc
