HIGH 7.2 PyPI

vantage6-server node accepts non-whitelisted algorithms from malicious server

GHSA-vc3v-ppc7-v486 · CVE-2023-47631 · PYSEC-2023-303 · PYSEC-2023-304

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

A node does not check if an image is allowed to run if a parent_id is set. A malicious party that breaches the server may modify it to set a fake parent_id and send a task of a non-whitelisted algorithm. The node will then execute it because the parent_id that is set prevents checks from being run. Relevant node code here

This impacts all servers that are breached by an expert user

Patches

Fixed in v4.1.2

Workarounds

None

Ready to move

Start Securing

Free, no credit card | First findings in minutes