Description
A vulnerability was found in wandb OpenUI up to 1.0/3.5-turb. Affected is the function generic_exception_handler of the file backend/openui/server.py of the component APIStatusError Handler. The manipulation of the argument key results in information exposure through error message. Access to the local network is required for this attack. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Problem types
Information Exposure Through Error Message
Product status
3.5-turb
Timeline
| 2026-03-27: | Advisory disclosed |
| 2026-03-27: | VulDB entry created |
| 2026-03-27: | VulDB entry last update |
Credits
Eric-b (VulDB User)
VulDB
References
vuldb.com/?id.353881 (VDB-353881 | wandb OpenUI APIStatusError server.py generic_exception_handler information exposure)
vuldb.com/?ctiid.353881 (VDB-353881 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.778266 (Submit #778266 | Weights and Biases OpenUI <= 1.0 (commit f9d8f0e) Generation of Error Message Containing Sensitive Information (CWE-209))
gist.github.com/YLChen-007/8c6ff147186855e4b716e7526de213e1