CVE-2026-15605

LOW

wandb Artifact Integrity Validation hashutil.py ArtifactManifestEntry.download weak hash

Title source: cna
STIX 2.1

Description

A security vulnerability has been detected in wandb 0.25.2.dev1. Affected is the function ArtifactManifestEntry.download in the library wandb/sdk/lib/hashutil.py of the component Artifact Integrity Validation. The manipulation leads to use of weak hash. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The pull request to fix this issue awaits acceptance.

References (7)

Core 7
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-378114 | wandb Artifact Integrity Validation hashutil.py ArtifactManifestEntry.download weak hash
https://vuldb.com/vuln/378114
Signature, Permissions Required signature permissions-required
VDB-378114 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/378114/cti
Third Party Advisory third-party-advisory
CVE-2026-15605 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15605
Third Party Advisory third-party-advisory
Submit #855675 | Weights & Biases wandb 0.25.2.dev1 at commit 28cc0bf5a9b529b72e5e501d0a48c6c42220ae0a; earlier versions may be affected if they use the same MD5-based CWE-328 Use of Weak Hash
https://vuldb.com/submit/855675
Issue Tracking issue-tracking
https://github.com/wandb/wandb/issues/12030
Patch issue-tracking patch
https://github.com/wandb/wandb/pull/12031

Scores

CVSS v3 3.1
EPSS 0.0015
EPSS Percentile 4.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-327 CWE-328
Status published
Products (1)
None/wandb 0.25.2.dev1
Published Jul 13, 2026
Tracked Since Jul 14, 2026