CVE-2026-15605
LOWwandb Artifact Integrity Validation hashutil.py ArtifactManifestEntry.download weak hash
Title source: cnaDescription
A security vulnerability has been detected in wandb 0.25.2.dev1. Affected is the function ArtifactManifestEntry.download in the library wandb/sdk/lib/hashutil.py of the component Artifact Integrity Validation. The manipulation leads to use of weak hash. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The pull request to fix this issue awaits acceptance.
References (7)
Core 7
Core References
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-378114 | wandb Artifact Integrity Validation hashutil.py ArtifactManifestEntry.download weak hash
https://vuldb.com/vuln/378114
Signature, Permissions Required signature
permissions-required
VDB-378114 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/378114/cti
Third Party Advisory third-party-advisory
CVE-2026-15605 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15605
Third Party Advisory third-party-advisory
Submit #855675 | Weights & Biases wandb 0.25.2.dev1 at commit 28cc0bf5a9b529b72e5e501d0a48c6c42220ae0a; earlier versions may be affected if they use the same MD5-based CWE-328 Use of Weak Hash
https://vuldb.com/submit/855675
Issue Tracking issue-tracking
https://github.com/wandb/wandb/issues/12030
Patch issue-tracking
patch
https://github.com/wandb/wandb/pull/12031
Product product
https://github.com/wandb/wandb/
Scores
CVSS v3
3.1
EPSS
0.0015
EPSS Percentile
4.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-327
CWE-328
Status
published
Products (1)
None/wandb
0.25.2.dev1
Published
Jul 13, 2026
Tracked Since
Jul 14, 2026