Impact
Weights & Biases wandb versions prior to 0.29.0 lack validation of file names returned from the backend in the File.download function. This omission allows an attacker who can control the backend to supply file names containing directory traversal sequences. The result is that files may be written outside the intended download directory, permitting modification of critical files such as shell startup scripts or Python import paths, which can lead to remote code execution.
Affected Systems
The vulnerability impacts the Wandb client package, vendored as wandb:wandb. Any deployment using wandb earlier than version 0.29.0 is susceptible, regardless of operating system, provided the client is able to fetch files from an attacker‑controlled backend.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and the EPSS score of 0.00731 (approximately 0.7%) shows a very low probability of exploitation. The lack of a KEV listing suggests it is not currently known to be exploited in the wild. Attackers would need control over the backend service to supply malicious file names; thus the attack vector is inferred to be an internal network or compromised backend. If successful, the attacker could overwrite configuration files or introduce malicious scripts, yielding code execution on the client system.
OpenCVE Enrichment