← Πίσω στην αναζήτηση CVE

CVE-2026-15605

wandb

Περιγραφή

A security vulnerability has been detected in wandb 0.25.2.dev1. Affected is the function ArtifactManifestEntry.download in the library wandb/sdk/lib/hashutil.py of the component Artifact Integrity Validation. The manipulation leads to use of weak hash. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The pull request to fix this issue awaits acceptance.

CVSS 3.1EPSS 0.151%Κίνδυνος 0.31
Προβολή πηγής
Δημοσίευση
2026-07-13 23:16:45
Επηρεαζόμενες εκδόσεις
<=0.25.2.dev1
Τύπος
Βιβλιοθήκη
Διάνυσμα
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N