Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-47w6-gwp4-w6vc

Опубликовано: 24 июл. 2026
Источник: github
Github: Прошло ревью
CVSS4: 7.1

Описание

vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review

Impact

Edit permission lacks ownership check, so another developer could alter metadata that is later trusted by nodes.

Worst they could do is update the image or image tag. If that is not noted, another image is approved than the one actually under review

Patches

No

Workarounds

No

Пакеты

Наименование

vantage6

pip
Затронутые версииВерсия исправления

<= 5.0.2

Отсутствует

EPSS

Процентиль: 11%
0.00207
Низкий

7.1 High

CVSS4

Дефекты

CWE-863

Связанные уязвимости

nvd
28 дней назад

vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an ownership check, allowing one algorithm developer to alter another developer's algorithm while it is pending or under review. The attacker can change metadata including the algorithm image or image tag, causing reviewers and nodes to trust a different image from the one originally submitted for approval. No fixed version is available as of this review.

EPSS

Процентиль: 11%
0.00207
Низкий

7.1 High

CVSS4

Дефекты

CWE-863