CVE-2024-7340: Weights \& Biases Weave
High severity, CVSS 8.8. EPSS: 5% chance of exploitation in the next 30 days.
The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse and leak arbitrary files remotely. In various common scenarios, this allows a low-privileged user to assume the role of the server admin.
Affected products
- Weights \& Biases Weave: up to and including 0.50.7
Published 2024-07-31. Last modified 2026-06-17.