SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-15605

LOW · CVSS 3.1 EPSS 0.15% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The vulnerability affects the Artifact Integrity Validation function in the wandb library, specifically in the download method, which utilizes a weak hash. Although the attack can be initiated remotely, it requires a high level of complexity, making exploitation difficult. Organizations using wandb 0.25.2.dev1 should prioritize monitoring this issue and consider applying the forthcoming fix to mitigate potential risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15605
Severity
LOW
CVSS
3.1
EPSS
0.15%

Original NVD Description

A security vulnerability has been detected in wandb 0.25.2.dev1. Affected is the function ArtifactManifestEntry.download in the library wandb/sdk/lib/hashutil.py of the component Artifact Integrity Validation. The manipulation leads to use of weak hash. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The pull request to fix this issue awaits acceptance.