PT-2026-67584 · Pypi · Vantage6

Published

2026-07-24

·

Updated

2026-07-24

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Impact

Edit permission lacks ownership check, so another developer could alter metadata that is later trusted by nodes.
Worst they could do is update the image or image tag. If that is not noted, another image is approved than the one actually under review

Patches

No

Workarounds

No

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-47W6-GWP4-W6VC

Affected Products

Vantage6