Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. vantage6
  4. ›
  5. GHSA-47w6-gwp4-w6vc

GHSA-47w6-gwp4-w6vc: vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review

July 24, 2026

Edit permission lacks ownership check, so another developer could alter metadata that is later trusted by nodes.

Worst they could do is update the image or image tag. If that is not noted, another image is approved than the one actually under review

References

  • github.com/advisories/GHSA-47w6-gwp4-w6vc
  • github.com/vantage6/vantage6/security/advisories/GHSA-47w6-gwp4-w6vc

Code Behaviors & Features

Detect and mitigate GHSA-47w6-gwp4-w6vc with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 5.0.2

Solution

Unfortunately, there is no solution available yet.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-863: Incorrect Authorization

Source file

pypi/vantage6/GHSA-47w6-gwp4-w6vc.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 25 Jul 2026 12:17:11 +0000.