Critical Path Traversal Vulnerability in Weights & Biases wandb: CVE-2026-91771
A critical path traversal vulnerability (CVE-2026-91771) has been discovered in Weights & Biases wandb versions before 0.29.0. This vulnerability allows attackers controlling the backend to supply malicious file names with directory traversal sequences, potentially leading to code execution. The vulnerability has a CVSS score of 8.8 and is considered high severity. Immediate patching to version 0.29.0 or later is recommended.