wandb
- Total products in the ecosystem
- 3
- Total vulnerabilities (90 days)
- 1
en
Verify to analyze this security profile
As of 09/18/2026, wandb recorded 1 security vulnerabilities in the last 90 days across 1 products, including 1 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, wandb had the most security vulnerabilities in the wandb ecosystem, with 1 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-91771Weights & Biases wandb before 0.29.0 Path Traversal via File Download | Exploitation statusNot confirmed | FixYes | Affected productwandb | Published09/15/2026 | SeverityHigh |
CVE-2026-4995wandb OpenUI Window Message Event index.html cross site scripting | Exploitation statusPublic exploit | FixNot confirmed | Affected productOpenUI | Published03/28/2026 | SeverityMedium |
CVE-2026-4994wandb OpenUI APIStatusError server.py generic_exception_handler information exposure | Exploitation statusPublic exploit | FixNot confirmed | Affected productOpenUI | Published03/28/2026 | SeverityMedium |
CVE-2026-4993wandb OpenUI config.py hard-coded credentials | Exploitation statusPublic exploit | FixNot confirmed | Affected productOpenUI | Published03/28/2026 | SeverityMedium |
CVE-2026-4992wandb OpenUI HTMLAnnotator server.py get_share HTML injection | Exploitation statusPublic exploit | FixNot confirmed | Affected productOpenUI | Published03/27/2026 | SeverityMedium |
CVE-2025-0192Stored Cross-site Scripting (XSS) in wandb/openui | Exploitation statusPublic exploit | FixNot confirmed | Affected productwandb/openui | Published03/20/2025 | SeverityMedium |
CVE-2024-10649Unauthenticated File Upload in wandb/openui | Exploitation statusPublic exploit | FixNot confirmed | Affected productwandb/openui | Published02/10/2025 | SeverityMedium |