vantage6 vulnerabilities
CVEs whose affected-version data names the vantage6 package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
18 CVEsRSS
CVE-2026-73652Highvantage6 is an open-source infrastructure for privacy preserving analysis
vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an ownership check, allowing one algorithm developer to alter another developer's algorith…
GHSA-47w6-gwp4-w6vcHighvantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
CVE-2024-24769LowVantage6: No limit on emails sent for password/MFA reset
Vantage6: No limit on emails sent for password/MFA reset
CVE-2024-27928MediumVantage6: 2FA can be circumvented with hacked email access
Vantage6: 2FA can be circumvented with hacked email access
CVE-2026-54533Mediumvantage6 node has an Improper Access Control issue
vantage6 node has an Improper Access Control issue
CVE-2026-54445MediumVantage6: Set admin user and password from environment or configuration
Vantage6: Set admin user and password from environment or configuration
CVE-2024-32969Low· 2.7vantage6 collaboration admins can extend their influence by expanding the collaboration
vantage6 collaboration admins can extend their influence by expanding the collaboration
CVE-2024-24770Medium· 5.3vantage6 vulnerable to a username timing attack on recover password/MFA token
vantage6 vulnerable to a username timing attack on recover password/MFA token
CVE-2024-23823Medium· 4.2vantage6's CORS settings overly permissive
vantage6's CORS settings overly permissive
CVE-2024-21649High· 8.8vantage6 remote code execution vulnerability
vantage6 remote code execution vulnerability
CVE-2024-22193Low· 3.5vantage6 may create unencrypted tasks in encrypted collaboration
vantage6 may create unencrypted tasks in encrypted collaboration
CVE-2024-21653Medium· 6.5vantage6 has insecure SSH configuration for node and server containers
vantage6 has insecure SSH configuration for node and server containers
CVE-2023-41881Low· 3.7vantage6 does not properly delete linked resources when deleting a collaboration
vantage6 does not properly delete linked resources when deleting a collaboration
CVE-2023-23930High· 7.2Pickle serialization vulnerable to Deserialization of Untrusted Data
Pickle serialization vulnerable to Deserialization of Untrusted Data
CVE-2023-28635Medium· 5.4Defining resource name as integer may give unintended access in vantage6
Defining resource name as integer may give unintended access in vantage6
CVE-2023-22738Medium· 6.5vantage6 vulnerable to Improper Preservation of Permissions
vantage6 vulnerable to Improper Preservation of Permissions
CVE-2023-23929High· 8.8vantage6 refresh tokens do not expire
vantage6 refresh tokens do not expire
CVE-2022-39228Medium· 6.5vantage6 vulnerable to Observable Response Discrepancy
vantage6 vulnerable to Observable Response Discrepancy