highVulnerability
GHSA-47w6-gwp4-w6vc
### Impact Edit permission lacks ownership check, so another developer could alter metadata that is later trusted by nodes. Worst they could do is update the image or image tag. If that is not noted, another image is approved than the one actually under review ### Patches No ### Workarounds No
Properties
- ghsa_id
- GHSA-47w6-gwp4-w6vc
- summary
- vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
- severity
- high
- cve_id
- GHSA-47w6-gwp4-w6vc
- is_ghsa_only
- true
- ghsa_published
- 2026-07-24T21:49:36Z
- source_url
- https://github.com/advisories/GHSA-47w6-gwp4-w6vc
- ghsa_updated
- 2026-07-24T21:49:40Z
Related Entities (4)
AFFECTS (1)
→[Software]pip/vantage6
HAS_WEAKNESS (1)
→[Weakness]Incorrect Authorization
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]pip/vantage6
Explore deeper with Ninja Signal's threat intelligence graph