vantage6 has 18 CVEs on record between 2023 and 2026. Disclosures have slowed: 2 in the last 90 days after 4 in the 90 before. The busiest recent month was June 2026 with 4. The median CVSS is 6.0 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.0
- Publish → KEV
- —
- Last 90 days
- 2 prev 4
Weakness classes
Products
- vantage6 18
Worst active — by depth score
CVE-2024-21649High· 8.8vantage6 remote code execution vulnerability49CVE-2023-23929High· 8.8vantage6 refresh tokens do not expire49CVE-2026-73652Highvantage6 is an open-source infrastructure for privacy preserving analysis41GHSA-47w6-gwp4-w6vcHighvantage6: Algorithm developer can edit another developer's algorithm that is pending / under review41CVE-2023-23930High· 7.2Pickle serialization vulnerable to Deserialization of Untrusted Data40
vantage6 vulnerabilities
CVEs affecting vantage6, newest first. Open any entry for full detail, references, and exploit status.
18 CVEsRSS
CVE-2026-73652Highvantage6 is an open-source infrastructure for privacy preserving analysis
vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an ownership check, allowing one algorithm developer to alter another developer's algorith…
GHSA-47w6-gwp4-w6vcHighvantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
CVE-2024-24769LowVantage6: No limit on emails sent for password/MFA reset
Vantage6: No limit on emails sent for password/MFA reset
CVE-2024-27928MediumVantage6: 2FA can be circumvented with hacked email access
Vantage6: 2FA can be circumvented with hacked email access
CVE-2026-54533Mediumvantage6 node has an Improper Access Control issue
vantage6 node has an Improper Access Control issue
CVE-2026-54445MediumVantage6: Set admin user and password from environment or configuration
Vantage6: Set admin user and password from environment or configuration
CVE-2024-32969Low· 2.7vantage6 collaboration admins can extend their influence by expanding the collaboration
vantage6 collaboration admins can extend their influence by expanding the collaboration
CVE-2024-24770Medium· 5.3vantage6 vulnerable to a username timing attack on recover password/MFA token
vantage6 vulnerable to a username timing attack on recover password/MFA token
CVE-2024-23823Medium· 4.2vantage6's CORS settings overly permissive
vantage6's CORS settings overly permissive
CVE-2024-21649High· 8.8vantage6 remote code execution vulnerability
vantage6 remote code execution vulnerability
CVE-2024-22193Low· 3.5vantage6 may create unencrypted tasks in encrypted collaboration
vantage6 may create unencrypted tasks in encrypted collaboration
CVE-2024-21653Medium· 6.5vantage6 has insecure SSH configuration for node and server containers
vantage6 has insecure SSH configuration for node and server containers
CVE-2023-41881Low· 3.7vantage6 does not properly delete linked resources when deleting a collaboration
vantage6 does not properly delete linked resources when deleting a collaboration
CVE-2023-23930High· 7.2Pickle serialization vulnerable to Deserialization of Untrusted Data
Pickle serialization vulnerable to Deserialization of Untrusted Data
CVE-2023-28635Medium· 5.4Defining resource name as integer may give unintended access in vantage6
Defining resource name as integer may give unintended access in vantage6
CVE-2023-22738Medium· 6.5vantage6 vulnerable to Improper Preservation of Permissions
vantage6 vulnerable to Improper Preservation of Permissions
CVE-2023-23929High· 8.8vantage6 refresh tokens do not expire
vantage6 refresh tokens do not expire
CVE-2022-39228Medium· 6.5vantage6 vulnerable to Observable Response Discrepancy
vantage6 vulnerable to Observable Response Discrepancy