github.com
https://github.com/vantage6/vantage6 CVE-2026-73652
HIGH
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
Record summary
CVE-2026-73652 has a selected CVSS score of 7.1 (high).
Description
vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an ownership check, allowing one algorithm developer to alter another developer's algorithm while it is pending or under review. The attacker can change metadata including the algorithm image or image tag, causing reviewers and nodes to trust a different image from the one originally submitted for approval. No fixed version is available as of this review.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 13, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
vantage6Browse vantage6 / vantage6 | CVE List | <= 5.0.2 | affected |
vantage6Browse PyPI / vantage6 | GitHub Advisory | Through 5.0.2 | affected |
References
2github.comConfirmation
https://github.com/vantage6/vantage6/security/advisories/GHSA-47w6-gwp4-w6vc