VYPR

Wandb

by Wandb

pypi: wandb

Source repositories

CVEs (2)

  • CVE-2026-91771HigSep 15, 2026
    risk 0.50cvss 8.8epss 0.01

    Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function, allowing path traversal attacks. Attackers controlling the backend can supply file names with directory traversal sequences to write files outside the…

  • CVE-2026-15605LowJul 13, 2026
    risk 0.20cvss 3.1epss 0.00

    A security vulnerability has been detected in wandb 0.25.2.dev1. Affected is the function ArtifactManifestEntry.download in the library wandb/sdk/lib/hashutil.py of the component Artifact Integrity Validation. The manipulation leads to use of weak hash. The attack may be…