weights_\&_biases Vulnerabilities and Affected Products
Vulnerabilities associated with weave.
Products
Clear product- weave1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
W&B Weave server remote arbitrary file leak and privilege escalationThe Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse and leak arbitrary files remotely. In various common scenarios, this allows a low-privileged user to assume the role of the server admin. | CVSS-v4.0 | EPSS4.97% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |