Junglewise Threat Intelligence

vantage6 Improper Access Control in node component

Severity: medium · CVSS 6.9 · Published 2026-06-05

Technologies: vantage6 (PyPI). Vendors: PyPI.

Executive brief

vantage6 is a framework for privacy-preserving federated learning. A security flaw in the vantage6 node component allows a malicious algorithm to access the input and output files of other algorithms running on the same node. This could lead to unauthorized data modification or interference with the results of other research tasks.

Technical details

An improper access control vulnerability (CWE-284) exists in the vantage6 node component for versions up to and including 3.3.3. The vulnerability allows a malicious algorithm container to bypass isolation and access the file system resources (input and output files) belonging to other algorithms executing on the same node. Exploitation occurs when a node executes a specially crafted malicious algorithm. While a formal patch is pending, administrators are advised to implement strict allow-lists for algorithm containers to mitigate the risk of running untrusted code.

Affected products

  • vantage6 vantage6 <= 3.3.3

Timeline

  • 2026-06-05: disclosed
  • 2026-06-05: advisory

References

Related threats