PT-2025-25341 · Vantage6 · Vantage6

Bartvanb

·

Published

2025-06-12

·

Updated

2025-09-17

·

CVE-2025-43863

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vantage6 versions prior to 4.11
Description The issue concerns an open-source framework designed for privacy-enhancing technologies such as Federated Learning and Multi-Party Computation. If an attacker gains access to an authenticated session, they can exploit the change password functionality to brute-force the user password. This is possible because the change password route can be called infinitely, providing feedback on incorrect passwords until the correct one is entered.
Recommendations For versions prior to 4.11, update to version 4.11 to resolve the issue.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

CVE-2025-43863
GHSA-J6G5-P62X-58HW
PYSEC-2025-220

Affected Products

Vantage6