CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-47w6-gwp4-w6vc: vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review

high
Impact Edit permission lacks ownership check, so another developer could alter metadata that is later trusted by nodes. Worst they could do is update the image or image tag. If that is not noted, another image is approved than the one actually under review Patches No Workarounds No

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
high
Published
2026-07-24
Last updated
2026-07-24
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-47w6-gwp4-w6vc

More from GitHub Security Advisories