MEDIUM4.2
PYSEC-2026-2004
vantage6's CORS settings overly permissive
Quick fix
PYSEC-2026-2004 — vantage6: upgrade to the fixed version with the command below.
pip install --upgrade 'vantage6>=4.3.0'Details
### Impact The vantage6 server has no restrictions on CORS settings. It should be possible for people to set the allowed origins of the server.
The impact is limited because v6 does not use session cookies
### Patches No
### Workarounds No
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/vantage6/vantage6/security/advisories/GHSA-4946-85pr-fvxh[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-23823[ADVISORY]
- https://github.com/vantage6/vantage6/commit/70bb4e1d889230a841eb364d6c03accd7dd01a41[WEB]
- https://github.com/vantage6/vantage6[PACKAGE]
- https://pypi.org/project/vantage6[PACKAGE]
- https://github.com/advisories/GHSA-4946-85pr-fvxh[ADVISORY]