Database/AI/ML frameworks & serving
Weights & Biases OpenUI: Unauthenticated endpoints allow file upload and download
CVSS 6.1CVE-2024-10649AI/ML frameworks & servingcurated
Impact
Unauthenticated endpoints allow file upload and download
Who can reach it
Unauthenticated network
What to do
Upgrade; only affects the OpenUI project, not the core W&B SDK
References
Related entries
- Dask distributed (+ Jupyter proxy): Exposure when Dask, JupyterLab and jupyter-server-proxy are combinedCVE-2026-23528 · Dask distributed (+ Jupyter proxy)Medium
- tract: unchecked size multiplication when reading an NNEF tensor gives a heap over-read on model loadCVE-2026-55093 · tract-nnef (read_tensor in nnef/src/tensors.rs)Medium
- tract: ONNX external_data path is not sanitised, so loading a model reads arbitrary local filesCVE-2026-55832 · tract-onnx (external_data path handling, get_external_resources / MmapDataResolver)Medium
- BentoML 1.3.9 (open redirect in the serving UI): A crafted URL against the BentoML server bounces the visitor to anNCVD-2025-017-bentoml-1-3-9-open-redirect-in-t · BentoML 1.3.9 (open redirect in the serving UI)Medium
- ClearML: Passwords stored in plaintext in MongoDBCVE-2024-24595 · ClearMLMedium
- JupyterLab: authenticated users bypass administrator plugin lock rules via /lab/api/pluginsCVE-2026-73627 · JupyterLab Extension/Plugin Manager (/lab/api/plugins lock-rule enforcement)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.