PT-2026-80674 · Pypi · Vantage6

Publicado

2026-08-19

·

Atualizado

2026-08-19

CVSS v4.0

7.1

Alta

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Impact

Edit permission lacks ownership check, so another developer could alter metadata that is later trusted by nodes.
Worst they could do is update the image or image tag. If that is not noted, another image is approved than the one actually under review

Patches

No

Workarounds

No

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

PYSEC-2026-3703

Produtos afetados

Vantage6