Dependency scanning
Check whether vantage6 is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2024-32969
vantage6 collaboration admins can extend their influence by expanding the collaboration
CVE-2024-23823
vantage6's CORS settings overly permissive
CVE-2024-21649
vantage6 remote code execution vulnerability
CVE-2024-22193
vantage6 may create unencrypted tasks in encrypted collaboration
CVE-2024-21653
vantage6 has insecure SSH configuration for node and server containers
CVE-2023-28635
Defining resource name as integer may give unintended access in vantage6
CVE-2023-23930
Pickle serialization vulnerable to Deserialization of Untrusted Data
CVE-2023-22738
vantage6 vulnerable to Improper Preservation of Permissions
CVE-2023-23929
vantage6 refresh tokens do not expire
CVE-2023-41881
vantage6 does not properly delete linked resources when deleting a collaboration
CVE-2026-73652
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
CVE-2026-73652
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
CVE-2024-27928
Vantage6: 2FA can be circumvented with hacked email access
CVE-2026-54445
Vantage6: Set admin user and password from environment or configuration
CVE-2024-24769
Vantage6: No limit on emails sent for password/MFA reset
CVE-2026-54533
vantage6 node has an Improper Access Control issue
CVE-2026-54533
vantage6 node has an Improper Access Control issue
CVE-2026-54445
Vantage6: Set admin user and password from environment or configuration
CVE-2024-24769
Vantage6: No limit on emails sent for password/MFA reset
CVE-2024-27928
Vantage6: 2FA can be circumvented with hacked email access
CVE-2024-23823
vantage6's CORS settings overly permissive
CVE-2022-39228
CVE-2022-39228
CVE-2022-39228
vantage6 vulnerable to Observable Response Discrepancy
CVE-2022-39228
CVE-2022-39228
CVE-2023-28635
Defining resource name as integer may give unintended access in vantage6
CVE-2024-21671
CVE-2024-21671
CVE-2024-21653
vantage6 has insecure SSH configuration for node and server containers
CVE-2024-24770
vantage6 vulnerable to a username timing attack on recover password/MFA token
CVE-2024-24770
vantage6 vulnerable to a username timing attack on recover password/MFA token
CVE-2024-32969
vantage6 collaboration admins can extend their influence by expanding the collaboration
CVE-2025-43863
vantage6 lacks brute-force protection on change password functionality
CVE-2025-43863
CVE-2025-43863
CVE-2023-41882
Improper Access Control in vantage6
CVE-2024-21649
CVE-2024-21649
CVE-2024-22193
CVE-2024-22193
CVE-2023-41882
CVE-2023-41882
CVE-2023-41881
CVE-2023-41881
CVE-2023-23930
CVE-2023-23930
CVE-2023-23929
CVE-2023-23929
CVE-2023-22738
CVE-2023-22738
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes