highVulnerability

GHSA-47w6-gwp4-w6vc

### Impact Edit permission lacks ownership check, so another developer could alter metadata that is later trusted by nodes. Worst they could do is update the image or image tag. If that is not noted, another image is approved than the one actually under review ### Patches No ### Workarounds No

Properties

ghsa_id
GHSA-47w6-gwp4-w6vc
summary
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
severity
high
cve_id
GHSA-47w6-gwp4-w6vc
is_ghsa_only
true
ghsa_published
2026-07-24T21:49:36Z
source_url
https://github.com/advisories/GHSA-47w6-gwp4-w6vc
ghsa_updated
2026-07-24T21:49:40Z

Related Entities (4)

AFFECTS (1)

[Software]pip/vantage6

HAS_WEAKNESS (1)

[Weakness]Incorrect Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/vantage6

Explore deeper with Ninja Signal's threat intelligence graph