PT-2026-28710 · Wandb · Wandb/Openui

Eric-B

+1

·

Published

2026-03-27

·

Updated

2026-03-28

·

CVE-2026-4992

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions wandb OpenUI versions up to 1.0
Description A flaw exists in wandb OpenUI, specifically within the HTMLAnnotator component. The issue resides in the create share/get share function located in the backend/openui/server.py file. Manipulation of the ID argument can lead to HTML injection, potentially allowing for remote attacks.
Recommendations Versions prior to 1.0 should be updated. As a temporary workaround, consider restricting access to the create share/get share function until a patch is available.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-4992

Affected Products

Wandb/Openui