CVE-2026-91771: Weights & Biases wandb before 0.29.0 Path Traversal via File Download

Published Sep 15, 2026
·
Updated

Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function, allowing path traversal attacks. Attackers controlling the backend can supply file names with directory traversal sequences to write files outside the intended download directory, potentially enabling code execution through modification of shell startup files or Python import paths.

Affected Software

1 affected component
Weights & Biases wandb<0.29.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Weights & Biases wandb to a version that resolves this vulnerability.

    Fixed in 0.29.0Patch Weights & Biases wandb before 0.29.0 Path Traversal via File Download

Event History

Sep 15, 2026
CVE Published
via MITRE·01:20 AM
Data Sourced
via MITRE·01:20 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue in practice?

An attacker must control the backend that supplies file-download responses to the wandb client. The vulnerable client then uses an attacker-controlled file name when downloading.

2

Are default wandb installations affected?

The issue affects wandb versions before 0.29.0 when the File.download function processes a malicious file name from a backend response. The provided information does not identify any configuration setting required to enable or disable the vulnerable behavior.

3

What can an attacker do with a successful exploit?

A malicious backend can use directory-traversal sequences to write files outside the intended download directory. This may enable code execution if the attacker can overwrite shell startup files or files in Python import paths.

4

What is the available remediation?

Upgrade Weights & Biases wandb to version 0.29.0 or later. This version includes the referenced fix for validation of downloaded file names.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203