40 Total advisories
40 Vulnerabilities
0 Malware

Dependency scanning

Check whether vantage6 is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

LOW 2.7
PyPI

CVE-2024-32969

vantage6 collaboration admins can extend their influence by expanding the collaboration

MEDIUM 4.2
PyPI

CVE-2024-23823

vantage6's CORS settings overly permissive

HIGH 8.8
PyPI

CVE-2024-21649

vantage6 remote code execution vulnerability

LOW 3.5
PyPI

CVE-2024-22193

vantage6 may create unencrypted tasks in encrypted collaboration

MEDIUM 6.5
PyPI

CVE-2024-21653

vantage6 has insecure SSH configuration for node and server containers

MEDIUM 5.4
PyPI

CVE-2023-28635

Defining resource name as integer may give unintended access in vantage6

HIGH 7.2
PyPI

CVE-2023-23930

Pickle serialization vulnerable to Deserialization of Untrusted Data

MEDIUM 6.5
PyPI

CVE-2023-22738

vantage6 vulnerable to Improper Preservation of Permissions

HIGH 8.8
PyPI

CVE-2023-23929

vantage6 refresh tokens do not expire

LOW 3.7
PyPI

CVE-2023-41881

vantage6 does not properly delete linked resources when deleting a collaboration

UNKNOWN
PyPI

CVE-2026-73652

vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review

UNKNOWN
PyPI

CVE-2026-73652

vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review

UNKNOWN
PyPI

CVE-2024-27928

Vantage6: 2FA can be circumvented with hacked email access

UNKNOWN
PyPI

CVE-2026-54445

Vantage6: Set admin user and password from environment or configuration

UNKNOWN
PyPI

CVE-2024-24769

Vantage6: No limit on emails sent for password/MFA reset

UNKNOWN
PyPI

CVE-2026-54533

vantage6 node has an Improper Access Control issue

UNKNOWN
PyPI

CVE-2026-54533

vantage6 node has an Improper Access Control issue

UNKNOWN
PyPI

CVE-2026-54445

Vantage6: Set admin user and password from environment or configuration

UNKNOWN
PyPI

CVE-2024-24769

Vantage6: No limit on emails sent for password/MFA reset

UNKNOWN
PyPI

CVE-2024-27928

Vantage6: 2FA can be circumvented with hacked email access

MEDIUM 4.2
PyPI

CVE-2024-23823

vantage6's CORS settings overly permissive

UNKNOWN
PyPI

CVE-2022-39228

CVE-2022-39228

MEDIUM 6.5
PyPI

CVE-2022-39228

vantage6 vulnerable to Observable Response Discrepancy

MEDIUM 6.5
PyPI

CVE-2022-39228

CVE-2022-39228

MEDIUM 5.4
PyPI

CVE-2023-28635

Defining resource name as integer may give unintended access in vantage6

LOW 3.7
PyPI

CVE-2024-21671

CVE-2024-21671

MEDIUM 6.5
PyPI

CVE-2024-21653

vantage6 has insecure SSH configuration for node and server containers

MEDIUM 5.3
PyPI

CVE-2024-24770

vantage6 vulnerable to a username timing attack on recover password/MFA token

MEDIUM 5.3
PyPI

CVE-2024-24770

vantage6 vulnerable to a username timing attack on recover password/MFA token

LOW 2.7
PyPI

CVE-2024-32969

vantage6 collaboration admins can extend their influence by expanding the collaboration

UNKNOWN
PyPI

CVE-2025-43863

vantage6 lacks brute-force protection on change password functionality

CRITICAL 9.8
PyPI

CVE-2025-43863

CVE-2025-43863

MEDIUM 5.4
PyPI

CVE-2023-41882

Improper Access Control in vantage6

HIGH 8.8
PyPI

CVE-2024-21649

CVE-2024-21649

MEDIUM 4.3
PyPI

CVE-2024-22193

CVE-2024-22193

MEDIUM 4.3
PyPI

CVE-2023-41882

CVE-2023-41882

MEDIUM 4.3
PyPI

CVE-2023-41881

CVE-2023-41881

HIGH 7.2
PyPI

CVE-2023-23930

CVE-2023-23930

UNKNOWN
PyPI

CVE-2023-23929

CVE-2023-23929

UNKNOWN
PyPI

CVE-2023-22738

CVE-2023-22738

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes