Vulnerability CVE-2024-7340


Published: 2024-07-31

Description:
The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse and leak arbitrary files remotely. In various common scenarios, this allows a low-privileged user to assume the role of the server admin.

 References:
https://research.jfrog.com/vulnerabilities/wandb-weave-server-remote-arbitrary-file-leak-jfsa-2024-001039248/
https://github.com/wandb/weave/pull/1657

Copyright 2026, cxsecurity.com

 

Back to Top