weights_\&_biases Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with weights_\&_biases products.
Products
- weave1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
W&B Weave server remote arbitrary file leak and privilege escalationThe Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse and leak arbitrary files remotely. In various common scenarios, this allows a low-privileged user to assume the role of the server admin. | CVSS-v4.0 | EPSS4.97% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |