Vulnerability Description
vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, malicious algorithms can potentially access other algorithms input and output files. Version 5.0.0 fixes the issue. As a workaround, verify and restrict the algorithm containers that are allowed to run on the node.
Related Weaknesses (CWE)
References
- https://docs.vantage6.ai/usage/running-the-node/security
- https://github.com/vantage6/vantage6/blob/main/docs/release_notes.rst#500
- https://github.com/vantage6/vantage6/issues/1932
- https://github.com/vantage6/vantage6/security/advisories/GHSA-x9f6-9rvm-mmrg
FAQ
What is CVE-2026-54533?
CVE-2026-54533 is a documented vulnerability. vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, malicious algorithms can potentially access other algorithms input and output files. Version 5.0.0 fi...
How severe is CVE-2026-54533?
CVSS scoring is not yet available for CVE-2026-54533. Check NVD for updates.
Is there a patch for CVE-2026-54533?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.