Description
Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function, allowing path traversal attacks. Attackers controlling the backend can supply file names with directory traversal sequences to write files outside the intended download directory, potentially enabling code execution through modification of shell startup files or Python import paths.
Published: 2026-09-15
Score: 8.7 High
EPSS: 1.2% Low
KEV: No
Impact: Path Traversal via File Download enabling arbitrary write and potential code execution
Action: Apply Patch
AI Analysis

Impact

Weights & Biases wandb versions prior to 0.29.0 lack validation of file names returned from the backend in the File.download function. This omission allows an attacker who can control the backend to supply file names containing directory traversal sequences. The result is that files may be written outside the intended download directory, permitting modification of critical files such as shell startup scripts or Python import paths, which can lead to remote code execution.

Affected Systems

The vulnerability impacts the Wandb client package, vendored as wandb:wandb. Any deployment using wandb earlier than version 0.29.0 is susceptible, regardless of operating system, provided the client is able to fetch files from an attacker‑controlled backend.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, and the EPSS score of 0.00731 (approximately 0.7%) shows a very low probability of exploitation. The lack of a KEV listing suggests it is not currently known to be exploited in the wild. Attackers would need control over the backend service to supply malicious file names; thus the attack vector is inferred to be an internal network or compromised backend. If successful, the attacker could overwrite configuration files or introduce malicious scripts, yielding code execution on the client system.

Generated by OpenCVE AI on September 17, 2026 at 18:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade wandb to version 0.29.0 or later to receive the fix for file name validation.
  • Configure the backend service to require authentication before allowing file downloads and to disallow directory traversal patterns in file names.
  • Update the client configuration to whitelist allowed download directories and reject any path containing traversal sequences.

Generated by OpenCVE AI on September 17, 2026 at 18:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 15 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Wandb
Wandb wandb
Vendors & Products Wandb
Wandb wandb

Tue, 15 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function, allowing path traversal attacks. Attackers controlling the backend can supply file names with directory traversal sequences to write files outside the intended download directory, potentially enabling code execution through modification of shell startup files or Python import paths.
Title Weights & Biases wandb before 0.29.0 Path Traversal via File Download
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:24.022Z

Reserved: 2026-09-15T00:45:12.423Z

Link: CVE-2026-91771

cve-icon Vulnrichment

Updated: 2026-09-18T17:16:58.510Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T02:16:49.680

Modified: 2026-09-24T21:08:22.573

Link: CVE-2026-91771

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-15T01:20:33Z

Links: CVE-2026-91771 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:15:14Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')