Use of Weak Hash Affecting wandb package, versions [0,]


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.15% (5th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Use of Weak Hash vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-WANDB-17966703
  • published14 Jul 2026
  • disclosed14 Jul 2026
  • creditDem0000000

Introduced: 14 Jul 2026

NewCVE-2026-15605  (opens in a new tab)
CWE-328  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

wandb is an A CLI and library for interacting with the Weights and Biases API.

Affected versions of this package are vulnerable to Use of Weak Hash through ArtifactManifestEntry.download in wandb/sdk/artifacts/artifact_manifest_entry.py and related artifact verification paths. An attacker can bypass or poison artifact integrity checks by supplying content that collides under the MD5-based digest comparison used for cached downloads and local file verification. This allows a substituted artifact file to be accepted as legitimate during download or verification, so users may load, cache, or verify tampered artifact contents instead of the expected file.

CVSS Base Scores

version 4.0
version 3.1