UNKNOWN PyPI

vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review

PYSEC-2026-3703 · CVE-2026-73652 · GHSA-47w6-gwp4-w6vc

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

Edit permission lacks ownership check, so another developer could alter metadata that is later trusted by nodes.

Worst they could do is update the image or image tag. If that is not noted, another image is approved than the one actually under review

Patches

No

Workarounds

No

Ready to move

Start Securing

Free, no credit card | First findings in minutes