Количество 2
Количество 2
CVE-2026-73652
vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an ownership check, allowing one algorithm developer to alter another developer's algorithm while it is pending or under review. The attacker can change metadata including the algorithm image or image tag, causing reviewers and nodes to trust a different image from the one originally submitted for approval. No fixed version is available as of this review.
GHSA-47w6-gwp4-w6vc
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-73652 vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an ownership check, allowing one algorithm developer to alter another developer's algorithm while it is pending or under review. The attacker can change metadata including the algorithm image or image tag, causing reviewers and nodes to trust a different image from the one originally submitted for approval. No fixed version is available as of this review. | 0% Низкий | 28 дней назад | ||
GHSA-47w6-gwp4-w6vc vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review | 0% Низкий | около 2 месяцев назад |
Уязвимостей на страницу